CVE-2019-9621: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.
Other sources
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS)to a version that resolves this vulnerability.Fixed in 8.6 patch 13 - Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS)to a version that resolves this vulnerability.Fixed in 8.7.11 patch 10 - Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS)to a version that resolves this vulnerability.Fixed in 8.8.10 patch 7 - Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS)to a version that resolves this vulnerability.Fixed in 8.8.11 patch 3 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2019-9621?
CVE-2019-9621 is a vulnerability in Zimbra Collaboration Suite that allows Server Side Request Forgery (SSRF) via the ProxyServlet component.
How severe is CVE-2019-9621?
CVE-2019-9621 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2019-9621?
The affected software versions include Zimbra Collaboration Server 8.6.0, 8.7.x (up to 8.7.11), and 8.8.x (up to 8.8.10).
How can I fix CVE-2019-9621?
To fix CVE-2019-9621, apply the relevant patches: patch 13 for 8.6, patch 10 for 8.7.x, and patch 7 or 8.8.11 patch 3 for 8.8.x.
Where can I find more information about CVE-2019-9621?
You can find more information about CVE-2019-9621 at the following references: [1](http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html), [2](http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html), [3](http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce)