← Back

CVE-2020-35123

nvd nist
Published: Dec 17, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.

Affected (28)

1 product
Collaboration
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Zimbra
After 8.8.0 to 8.8.15
Version 8.8.15
Version 8.8.15 p10
Version 8.8.15 p11
Version 8.8.15 p12
Version 8.8.15 p13
Version 8.8.15 p14
Version 8.8.15 p15
Version 8.8.15 p16
Version 8.8.15 p1
Version 8.8.15 p2
Version 8.8.15 p3
Version 8.8.15 p4
Version 8.8.15 p5
Version 8.8.15 p6
Version 8.8.15 p7
Version 8.8.15 p8
Version 8.8.15 p9
Version 9.0.0
Version 9.0.0 p1
Version 9.0.0 p2
Version 9.0.0 p3
Version 9.0.0 p4
Version 9.0.0 p5
Version 9.0.0 p6
Version 9.0.0 p7
Version 9.0.0 p8
Version 9.0.0 p9

References (8)

Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
Third Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.