Junglewise Threat Intelligence

CVE-2016-3401: Zimbra Collaboration integrity vulnerability via unknown vectors

CVE-2016-3401 · Severity: medium · CVSS 6.5 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration. Vendors: Synacor, Zimbra.

Executive brief

Zimbra Collaboration is an enterprise-grade email and collaboration platform. A vulnerability in versions prior to 8.7.0 allows authenticated users to perform unauthorized actions that compromise the integrity of the system. This could lead to the modification of data or settings by individuals who already have access to the platform.

Technical details

This is an unspecified vulnerability (CWE-noinfo) in Zimbra Collaboration versions prior to 8.7.0. The flaw allows a remote attacker with valid authentication credentials to impact the integrity of the system. While the specific root cause and vulnerable component are not publicly detailed (referenced internally as bug 99810), the attack vector is network-based and does not require user interaction. The vulnerability was addressed in the Zimbra Collaboration 8.7.0 GA release. Security engineers should ensure their Zimbra instances are upgraded to version 8.7.0 or later to mitigate this risk.

Affected products

  • Zimbra Zimbra Collaboration before 8.7.0

Timeline

  • 2016-07-01: patched: Fixed in Zimbra Collaboration 8.7.0 GA release
  • 2017-01-18: disclosed: NVD publication date

References

Related threats