CVE-2017-6813: Critical severity zimbra collaboration suite vulnerability
Published May 23, 2017
·Updated
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.
Affected Software
1 affected component
Synacor Zimbra Collaboration Suite<=8.7.5
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-6813?
The severity of CVE-2017-6813 is classified as medium due to improper privilege management in Zimbra Collaboration Suite.
2
How do I fix CVE-2017-6813?
To fix CVE-2017-6813, you should upgrade Zimbra Collaboration Suite to version 8.7.6 or later.
3
What operations are affected by CVE-2017-6813?
CVE-2017-6813 affects operations that require certain privileges which were not enforced in earlier versions of Zimbra Collaboration Suite.
4
Which versions of Zimbra Collaboration Suite are vulnerable to CVE-2017-6813?
Zimbra Collaboration Suite versions before 8.7.6, including 8.7.5 or earlier, are vulnerable to CVE-2017-6813.
5
What are the consequences of exploiting CVE-2017-6813?
Exploiting CVE-2017-6813 can allow unauthorized users to perform actions that require higher privileges on the Zimbra system.