Executive brief
A vulnerability in Zimbra Collaboration Suite, a popular enterprise email and collaboration platform, allows remote attackers to compromise the integrity of the system. This could potentially allow unauthorized modifications to data or system configurations, impacting the reliability of corporate communications. Organizations using versions prior to 8.7.0 are at risk and should upgrade to ensure the security of their email infrastructure.
Technical details
An unspecified vulnerability (internally tracked as bug 104477) exists in Zimbra Collaboration Suite versions prior to 8.7.0. The flaw allows remote, unauthenticated attackers to impact the integrity of the system via unknown vectors. Based on the CVSS:3.0 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), the attack can be carried out over the network with low complexity and requires no special privileges or user interaction. While specific technical details regarding the root cause are not publicly disclosed, the issue is resolved in the 8.7.0 GA release.
Affected products
- Zimbra Zimbra Collaboration Suite before 8.7.0
Timeline
- 2016-01-01: patched: Fixed in Zimbra Collaboration 8.7.0 GA release
- 2017-01-18: disclosed: NVD publication date