Executive brief
Zimbra Collaboration is an enterprise-grade email and collaboration platform. A vulnerability in versions prior to 8.7.0 allows remote attackers to compromise the integrity of the system, potentially leading to unauthorized modification of data or configuration. This could impact the reliability of corporate communications and the accuracy of stored information.
Technical details
This is an unspecified vulnerability in Zimbra Collaboration (formerly Zimbra Collaboration Suite) prior to version 8.7.0. The flaw is tracked internally by Zimbra as bug 103996. According to the CVSS metrics, the vulnerability is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N) and specifically impacts the integrity of the system (I:H) while having no reported impact on confidentiality or availability. While the exact root cause is not publicly detailed in the advisory, the issue was addressed in the 8.7.0 GA release. Security engineers should upgrade to version 8.7.0 or later to mitigate this risk.
Affected products
- Zimbra Zimbra Collaboration before 8.7.0
Timeline
- 2017-01-18: disclosed: NVD publication date
- 2016-07-13: patched: Zimbra 8.7.0 release date