CVE-2020-35123: XEE
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35123?
CVE-2020-35123 is a vulnerability in Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17 that allows for XXE attacks.
How severe is CVE-2020-35123?
CVE-2020-35123 has a severity level of 6.5 (medium).
How can I fix CVE-2020-35123?
To fix CVE-2020-35123, you need to update Zimbra Collaboration Suite Network Edition to version 9.0.0 Patch 10 or version 8.8.15 Patch 17.
Where can I find more information about CVE-2020-35123?
You can find more information about CVE-2020-35123 in the Zimbra Security Center and the Zimbra Release pages for version 8.8.15 P17 and 9.0.0 P10.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-35123?
The CWE ID for CVE-2020-35123 is 611.