Executive brief
A vulnerability in Zimbra Collaboration allows remote attackers to access sensitive information. Zimbra Collaboration is an enterprise-grade email and collaboration platform; an exploit could lead to the unauthorized exposure of private communications or user data. Organizations using versions older than 8.7.0 are at risk of data confidentiality breaches.
Technical details
This is an unspecified vulnerability in Zimbra Collaboration (formerly Zimbra Collaboration Suite) prior to version 8.7.0. The flaw allows a remote, unauthenticated attacker to compromise the confidentiality of the system via unknown vectors, identified internally by the vendor as bug 99167. While specific technical root causes are not disclosed in the advisory, the CVSS vector indicates a network-based attack with low complexity and no requirement for user interaction or privileges. The issue was addressed in the Zimbra 8.7.0 GA release.
Affected products
- Zimbra Zimbra Collaboration before 8.7.0
Timeline
- 2017-01-18: advisory: NVD publication date
- 2016-07-13: patched: Zimbra 8.7.0 release date