CVE-2016-9924: XEE
Published Mar 29, 2017
·Updated
Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
Affected Software
1 affected component
Synacor Zimbra Collaboration Suite<=8.7.3
Event History
Mar 29, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9924?
CVE-2016-9924 is considered a medium severity vulnerability that allows for XML External Entity (XXE) attacks.
2
How do I fix CVE-2016-9924?
To remediate CVE-2016-9924, upgrade Zimbra Collaboration Suite to version 8.7.4 or later.
3
Who is affected by CVE-2016-9924?
CVE-2016-9924 affects users of Zimbra Collaboration Suite versions prior to 8.7.4.
4
What type of attacks can CVE-2016-9924 facilitate?
CVE-2016-9924 can facilitate malicious XML External Entity (XXE) attacks, potentially exposing sensitive data.
5
Is there a workaround for CVE-2016-9924?
There are no official workarounds for CVE-2016-9924; upgrading to the latest version is recommended.