Executive brief
A vulnerability in Zimbra Collaboration versions prior to 8.7.0 allows remote attackers to compromise the integrity of the system. This could potentially allow unauthorized modifications to email data or system configurations, impacting the reliability of the communication platform. Organizations using affected versions should upgrade to version 8.7.0 or later to ensure the security of their messaging environment.
Technical details
An unspecified vulnerability in Zimbra Collaboration (formerly Zimbra Collaboration Suite) before version 8.7.0 allows remote attackers to affect system integrity. The vulnerability is tracked internally by the vendor as bug 103959. While specific technical details regarding the root cause or vulnerable component are not publicly disclosed, the CVSS 3.0 vector indicates a network-based attack vector with low complexity and no required user interaction or privileges. Successful exploitation allows an attacker to perform high-impact integrity violations. The issue is resolved in Zimbra Collaboration 8.7.0.
Affected products
- Zimbra Zimbra Collaboration before 8.7.0
Timeline
- 2017-01-18: advisory: NVD publication date
- 2016-07-13: patched: Release date of Zimbra 8.7.0