CVE-2019-9621

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
References
Link Resource
http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html
http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce Exploit Third Party Advisory
https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html Third Party Advisory
https://blog.zimbra.com/2019/03/9826/ Vendor Advisory
https://bugzilla.zimbra.com/show_bug.cgi?id=109127
https://wiki.zimbra.com/wiki/Security_Center Release Notes Vendor Advisory
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
https://www.exploit-db.com/exploits/46693/ Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html
http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce Exploit Third Party Advisory
https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html Third Party Advisory
https://blog.zimbra.com/2019/03/9826/ Vendor Advisory
https://bugzilla.zimbra.com/show_bug.cgi?id=109127
https://wiki.zimbra.com/wiki/Security_Center Release Notes Vendor Advisory
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
https://www.exploit-db.com/exploits/46693/ Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zimbra:collaboration_server:*:*:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:*:*:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:*:*:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:-:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p1:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p10:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p11:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p12:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p2:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p3:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p4:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p5:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p6:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p7:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p8:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.6.0:p9:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:-:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p1:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p2:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p3:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p4:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p5:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p6:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p7:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p8:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.7.11:p9:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.10:-:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.10:p1:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.10:p2:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.10:p3:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.10:p4:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.10:p5:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.10:p6:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.11:-:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.11:p1:*:*:*:*:*:*
cpe:2.3:a:zimbra:collaboration_server:8.8.11:p2:*:*:*:*:*:*

History

21 Nov 2024, 04:51

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html - Exploit, Third Party Advisory, VDB Entry
References () http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html - () http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html -
References () http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce - Exploit, Third Party Advisory () http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce - Exploit, Third Party Advisory
References () https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html - Third Party Advisory () https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html - Third Party Advisory
References () https://blog.zimbra.com/2019/03/9826/ - Vendor Advisory () https://blog.zimbra.com/2019/03/9826/ - Vendor Advisory
References () https://bugzilla.zimbra.com/show_bug.cgi?id=109127 - () https://bugzilla.zimbra.com/show_bug.cgi?id=109127 -
References () https://wiki.zimbra.com/wiki/Security_Center - Release Notes, Vendor Advisory () https://wiki.zimbra.com/wiki/Security_Center - Release Notes, Vendor Advisory
References () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - Vendor Advisory () https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories - Vendor Advisory
References () https://www.exploit-db.com/exploits/46693/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/46693/ - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2019-04-30 18:29

Updated : 2024-11-21 04:51


NVD link : CVE-2019-9621

Mitre link : CVE-2019-9621

CVE.ORG link : CVE-2019-9621


JSON object : View

Products Affected

zimbra

  • collaboration_server
CWE
CWE-918

Server-Side Request Forgery (SSRF)