CVE-2022-37042
Summary
| CVE | CVE-2022-37042 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-12 15:15:16 UTC |
| Updated | 2026-08-04 05:16:29 UTC |
| Description | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.918930000 probability, percentile 0.998090000 (date 2026-08-12)
CISA KEV: Listed on 2022-08-11; due 2022-09-01; ransomware use Known
Problem Types: CWE-22 | n/a | CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | Synacor |
|---|---|
| Product | Zimbra Collaboration Suite (ZCS) |
| Name | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/; https://nvd.nist.gov/vuln/detail/CVE-2022-37042 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | - | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p1 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p10 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p11 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p12 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p13 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p14 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p15 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p16 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p17 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p18 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p19 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p2 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p20 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p21 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p22 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p23 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p24 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p25 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p26 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p27 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p28 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p29 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p3 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p30 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p31 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p31.1 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p32 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p4 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p5 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p6 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p7 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p8 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 8.8.15 | p9 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | - | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p1 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p10 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p11 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p12 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p13 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p14 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p15 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p16 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p17 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p18 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p19 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p2 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p20 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p21 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p22 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p23 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p24 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p24.1 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p25 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p3 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p4 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p5 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p6 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p7 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p8 | All | All |
| Application | Synacor | Zimbra Collaboration Suite | 9.0.0 | p9 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| wiki.zimbra.com/wiki/Security_Center | af854a3a-2127-422b-91ae-364da2661108 | wiki.zimbra.com | Patch, Vendor Advisory |
| wiki.zimbra.com/wiki/Zimbra_Security_Advisories | af854a3a-2127-422b-91ae-364da2661108 | wiki.zimbra.com | Vendor Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-08-11T00:00:00.000Z | CVE-2022-37042 added to CISA KEV |
Legacy QID Mappings
- 377759 Zimbra Collaboration Suite Authentication Bypass Vulnerability