Executive brief
Zimbra Collaboration is a widely used enterprise email and collaboration platform. Multiple security flaws in versions prior to 8.7.0 could allow remote attackers to compromise the integrity of the system, potentially leading to unauthorized modifications of data or system configurations. Organizations using affected versions should upgrade to maintain the security of their communications and user data.
Technical details
This advisory covers multiple unspecified vulnerabilities (internally tracked as bugs 103961 and 104828) in Zimbra Collaboration Suite. The flaws allow remote attackers to impact system integrity via unknown vectors without requiring authentication or user interaction. The vulnerabilities were addressed in the release of Zimbra Collaboration 8.7.0. Due to the 'unspecified' nature of the report, the exact root cause (e.g., injection, logic error, or improper validation) is not publicly documented, but the CVSS metrics indicate a network-based attack vector with high integrity impact.
Affected products
- Zimbra Zimbra Collaboration Suite before 8.7.0
Timeline
- 2017-01-18: disclosed: NVD publication date
- 2016-07-13: patched: Zimbra 8.7.0 GA release date