CVE-2014-8563: OS Command Injection
Published Jan 27, 2020
·Updated
Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
Affected Software
1 affected component
Synacor Zimbra Collaboration Server<8.0.9
Event History
Jan 27, 2020
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2014-8563.
2
What is the severity of CVE-2014-8563?
The severity of CVE-2014-8563 is critical, with a CVSS score of 9.8.
3
What is the description of CVE-2014-8563?
CVE-2014-8563 is a vulnerability in Synacor Zimbra Collaboration before 8.0.9 that allows plaintext command injection during STARTTLS.
4
What software is affected by CVE-2014-8563?
Synacor Zimbra Collaboration Server versions up to exclusive 8.0.9 are affected by CVE-2014-8563.
5
How can I fix CVE-2014-8563?
To fix CVE-2014-8563, upgrade Synacor Zimbra Collaboration Server to version 8.0.9 or later.