CVE-2019-9621
Synacor · Published April 30, 2019
7.5
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
Affected Products
- Zimbra Collaboration Suite < 8.6.0
- Zimbra Collaboration Suite < 8.7.11
- Zimbra Collaboration Suite < 8.8.9
- Zimbra Collaboration Suite
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N