CVE-2018-10951: Medium severity zimbra collaboration suite vulnerability
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-10951.
What is the severity of CVE-2018-10951?
The severity of CVE-2018-10951 is medium with a severity value of 6.5.
What software versions are affected by this vulnerability?
This vulnerability affects Zimbra Collaboration Suite versions 8.8 before 8.8.8, 8.7 before 8.7.11.Patch3, and 8.6 before 8.6.0.Patch10.
How can an attacker exploit CVE-2018-10951?
An attacker can exploit CVE-2018-10951 by making a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API to gain zimbraSSLPrivateKey read access.
Where can I find more information about this vulnerability?
More information about CVE-2018-10951 can be found at the following link: https://bugzilla.zimbra.com/show_bug.cgi?id=108894.