CVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.
Other sources
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS)to a version that resolves this vulnerability.Fixed in 8.8.15 Patch 7 - Configuration
If WebEx zimlet is installed, disable zimlet JSP because ZCS before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
Synacor Zimbra Collaboration Suite (ZCS) zimlet JSP = disabled - Compensating control
If mitigations are unavailable, discontinue use of the product.
Event History
Frequently Asked Questions
What is CVE-2020-7796?
CVE-2020-7796 is a vulnerability in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 that allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
Which software versions are affected by CVE-2020-7796?
CVE-2020-7796 affects Zimbra Collaboration Suite versions up to and including 8.8.15.
What is the severity of CVE-2020-7796?
CVE-2020-7796 has a severity rating of 9.8, which is classified as critical.
How can I fix CVE-2020-7796?
To fix CVE-2020-7796, you need to update Zimbra Collaboration Suite to version 8.8.15 Patch 7 or later.
Where can I find more information about CVE-2020-7796?
You can find more information about CVE-2020-7796 on the Zimbra Collaboration Suite wiki page: [https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7](https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7)