← Back

CVE-2018-10951

nvd nist
Published: May 10, 2018Modified: Aug 15, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.

Affected (14)

1 product
Zimbra Collaboration Suite
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Synacor
From 8.7.0 to 8.7.11
From 8.8.0 to 8.8.8
Version 8.6.0
Version 8.6.0 patch1
Version 8.6.0 patch2
Version 8.6.0 patch3
Version 8.6.0 patch4
Version 8.6.0 patch5
Version 8.6.0 patch6
Version 8.6.0 patch7
Version 8.6.0 patch8
Version 8.6.0 patch9
Version 8.7.11 p1
Version 8.7.11 p2

References (2)

Source: cve@mitre.org
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.