CVE-2016-3415: Critical severity Synacor Zimbra Collaboration Suite vulnerability
Published Jan 18, 2017
·Updated
Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.
Affected Software
1 affected component
Synacor Zimbra Collaboration Suite<=8.6.0
Event History
Jan 18, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-3415?
CVE-2016-3415 has been classified as a medium severity vulnerability due to the potential for remote exploitation.
2
How do I fix CVE-2016-3415?
To mitigate CVE-2016-3415, upgrade Zimbra Collaboration to version 8.7.0 or later.
3
What types of attacks are possible with CVE-2016-3415?
CVE-2016-3415 allows remote attackers to conduct deserialization attacks.
4
What versions of Zimbra are affected by CVE-2016-3415?
CVE-2016-3415 affects all versions of Zimbra Collaboration before 8.7.0, specifically up to 8.6.0.
5
Is there a patch available for CVE-2016-3415?
Yes, a patch is available through the upgrade to Zimbra Collaboration version 8.7.0 or later.