QID 376769
Date Published: 2022-08-05
QID 376769: Zimbra Collaboration Multiple Vulnerabilities
Zimbra is a complete email, address book, calendar and tasks solution that can be accessed from the Zimbra Web Client, Zimbra Desktop offline client, Outlook and a variety of other standards-based email clients and mobile devices.
Affected Software:
Zimbra Collaboration Suite 8.8.15
Zimbra Collaboration Suite 9.0
QID Detection Logic:
This QID runs "zmcontrol -v" to check the vulnerable version
Successful exploitation could allow an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance.
Solution
Vendor has released patched versions Zimbra 9.0.0 Patch 24 and 8.8.15 Patch 31 to fix this issue. For more details please refer to Zimbra
Vendor References
- Zimbra Security_Advisory -
wiki.zimbra.com/wiki/Zimbra_Security_Advisories
CVEs related to QID 376769
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-27924 |
|