Junglewise Threat Intelligence

CVE-2016-3405: Zimbra Collaboration multiple unspecified vulnerabilities

CVE-2016-3405 · Severity: high · CVSS 7.5 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration Suite. Vendors: Synacor, Zimbra.

Executive brief

Zimbra Collaboration is a widely used enterprise email and collaboration platform. Multiple security flaws in versions prior to 8.7.0 could allow remote attackers to compromise the integrity of the system, potentially leading to unauthorized modifications of data or system configurations. Organizations using affected versions should upgrade to maintain the security of their communications and user data.

Technical details

This advisory covers multiple unspecified vulnerabilities (internally tracked as bugs 103961 and 104828) in Zimbra Collaboration Suite. The flaws allow remote attackers to impact system integrity via unknown vectors without requiring authentication or user interaction. The vulnerabilities were addressed in the release of Zimbra Collaboration 8.7.0. Due to the 'unspecified' nature of the report, the exact root cause (e.g., injection, logic error, or improper validation) is not publicly documented, but the CVSS metrics indicate a network-based attack vector with high integrity impact.

Affected products

  • Zimbra Zimbra Collaboration Suite before 8.7.0

Timeline

  • 2017-01-18: disclosed: NVD publication date
  • 2016-07-13: patched: Zimbra 8.7.0 GA release date

References

Related threats