Junglewise Threat Intelligence

CVE-2016-4019: Zimbra Collaboration Suite integrity vulnerability via unknown vectors

CVE-2016-4019 · Severity: high · CVSS 7.5 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration Suite. Vendors: Synacor, Zimbra.

Executive brief

A vulnerability in Zimbra Collaboration Suite, a popular enterprise email and collaboration platform, allows remote attackers to compromise the integrity of the system. This could potentially allow unauthorized modifications to data or system configurations, impacting the reliability of corporate communications. Organizations using versions prior to 8.7.0 are at risk and should upgrade to ensure the security of their email infrastructure.

Technical details

An unspecified vulnerability (internally tracked as bug 104477) exists in Zimbra Collaboration Suite versions prior to 8.7.0. The flaw allows remote, unauthenticated attackers to impact the integrity of the system via unknown vectors. Based on the CVSS:3.0 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), the attack can be carried out over the network with low complexity and requires no special privileges or user interaction. While specific technical details regarding the root cause are not publicly disclosed, the issue is resolved in the 8.7.0 GA release.

Affected products

  • Zimbra Zimbra Collaboration Suite before 8.7.0

Timeline

  • 2016-01-01: patched: Fixed in Zimbra Collaboration 8.7.0 GA release
  • 2017-01-18: disclosed: NVD publication date

References

Related threats