CVE-2019-9621
Published Apr 30, 2019
Last updated 5 years ago
Overview
- Description
- Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-918
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:zimbra:collaboration_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58B5F91A-E6B3-4020-AFAF-AE9830F07203", "versionEndExcluding": "8.6.0" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1387AC8-F393-421E-A0C6-E9BB1A0FE39D", "versionEndExcluding": "8.7.11", "versionStartIncluding": "8.7.0" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19953218-6103-4689-BE3D-6CC2F240FB3F", "versionEndExcluding": "8.8.10", "versionStartIncluding": "8.8.0" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34C10FC4-6B08-46EA-9DBC-C38BC51C43DA" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF7FE7FE-4BFF-4381-94B9-CE59308E0303" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D4B1DF9D-F603-469D-B5E7-8BFB48517780" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p11:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B9F25B4-D10E-4C43-8309-C27015B44E1F" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p12:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A17C648F-8CFE-4418-8EBF-80757ABF67DA" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CFFD07C7-3E61-4C2C-82C2-4BE0F392BE3D" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63C3A9C3-033B-4730-B1D4-BA4B2EA1E717" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D45EA214-8E61-46B9-B5E3-E1F2048436C1" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E341AFD-76EE-4D69-842E-E9E69A6482F1" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "32B34C20-8F04-419D-8F69-A15DB1BD1DE3" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1D3A234-603E-47FC-AC89-F868BEF557E4" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB10A55D-3708-4C7E-8B15-C28AFB80ADED" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.6.0:p9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1E7168D-2BB7-4CC1-92B3-AFA4CECC4440" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CC3B2D35-FC6E-45CB-A0D1-F3EDD4035094" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27F59D2D-BE7E-490F-8C7B-09145FF18243" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B815B700-6242-434E-A4DF-50CAF01F7088" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB38E99F-B630-4389-8159-6E8ED61416DA" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D1B6501F-8E63-4672-A40F-D79D068861CD" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "815E22AF-7406-4B70-9A85-F9E6B875A3E5" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42C87747-2220-4856-8AEF-EF6F7C889FCC" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E809B8B9-829B-4483-B85C-0B58A73BD24B" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9939EE2E-99C6-4697-9385-E470D31416B0" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.7.11:p9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D42CECDD-9DD7-4C24-ACCD-C2F876A2750F" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.10:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "325FBDCD-13CB-4DC6-BBAA-592F37FDE5C0" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.10:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19CD7665-5C06-46AF-B2D6-5ED0000AF98C" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.10:p2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A945C9FA-DA43-426D-8E02-4FCBC8A2B8FD" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.10:p3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8254749E-E88D-44D5-9644-B6DD3E7574C9" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.10:p4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B468616F-0F41-4F53-98A3-102617A92C59" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.10:p5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14BEBF0D-F2C1-49D9-A02F-7CD6B4D81D55" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.10:p6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C8CF223-3E24-4452-9B3C-701F15680584" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.11:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25546B97-61AA-480F-AA66-9F6C0DD25F23" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.11:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD145A57-203B-450A-B79B-602C66BCE58C" }, { "criteria": "cpe:2.3:a:zimbra:collaboration_server:8.8.11:p2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB0E3CA9-6687-483A-8BC4-6046AC7A846F" } ], "operator": "OR" } ] } ]