QID 378407
QID 378407: Zimbra Collaboration Strengthened PreAuth Servlet Vulnerability
Zimbra Collaboration, formerly known as the Zimbra Collaboration Suite before 2019, is a collaborative software suite that includes an email server and a web client.
Affected Versions:
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0.0
QID Detection Logic:
This QID checks for vulnerable version of Zimbra Collaboration Suite using the "runuser -l zimbra -c 'zmcontrol -v'" command.
Successful exploitation of the vulnerability may lead security issues related to open redirection vulnerabilities
Solution
Vendor has released patch. For more information please refer to Zimbra Security Advisory.
Vendor References
- Zimbra Security Advisory -
wiki.zimbra.com/wiki/Security_Center
CVEs related to QID 378407
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zimbra Security Advisory |
|