QID 379374
Date Published: 2024-03-20
QID 379374: Zimbra Collaboration Suite (ZCS) Multiple Vulnerabilities
Zimbra is a complete email, address book, calendar and tasks solution that can be accessed from the Zimbra Web Client, Zimbra Desktop offline client, Outlook and a variety of other standards-based email clients and mobile devices.
In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 44, 9 before 9.0.0 Patch 37, and 10 before 10.0.5, internal JSP and XML files can be exposed.
Affected Software:
Synacor Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 44
Synacor Zimbra Collaboration Suite 9.0.x before 9.0.0 Patch 37
Synacor Zimbra Collaboration Suite 10.0.x before 10.0.5
QID Detection Logic:
This QID runs "zmcontrol -v" to check the vulnerable version
Successful exploitation of this issue allows an attacker to compromise confidentiality and integrity
- Zimbra Security Advisories -
wiki.zimbra.com/wiki/Zimbra_Security_Advisories
CVEs related to QID 379374
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zimbra |
|