← Back

CVE-2019-9621

Published: Apr 30, 2019Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

Affected (48)

1 product
Zimbra Collaboration Suite
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Synacor
Before 8.6.0
From 8.7.0 to 8.7.11
From 8.8.0 to 8.8.9
Version 8.6.0
Version 8.6.0 patch10
Version 8.6.0 patch11
Version 8.6.0 patch12
Version 8.6.0 patch1
Version 8.6.0 patch2
Version 8.6.0 patch3
Version 8.6.0 patch4
Version 8.6.0 patch5
Version 8.6.0 patch6
Version 8.6.0 patch7
Version 8.6.0 patch8
Version 8.6.0 patch9
Version 8.7.11
Version 8.7.11 patch10
Version 8.7.11 patch1
Version 8.7.11 patch2
Version 8.7.11 patch3
Version 8.7.11 patch4
Version 8.7.11 patch5
Version 8.7.11 patch6
Version 8.7.11 patch7
Version 8.7.11 patch8
Version 8.7.11 patch9
Version 8.8.10
Version 8.8.10 patch1
Version 8.8.10 patch2
Version 8.8.10 patch3
Version 8.8.10 patch4
Version 8.8.10 patch6
Version 8.8.10 patch7
Version 8.8.11
Version 8.8.11 patch1
Version 8.8.11 patch2
Version 8.8.11 patch3
Version 8.8.9
Version 8.8.9 p5
Version 8.8.9 patch1
Version 8.8.9 patch2
Version 8.8.9 patch3
Version 8.8.9 patch4
Version 8.8.9 patch6
Version 8.8.9 patch7
Version 8.8.9 patch8
Version 8.8.9 patch9

References (19)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.