First published: Mon Jul 31 2023(Updated: )
In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra | >=8.8.0<8.8.15 | |
Zimbra | =8.8.15-p11 | |
Zimbra | =8.8.15-p26 | |
Zimbra | =8.8.15-p3 | |
Zimbra | =8.8.15-p30 | |
Zimbra | =8.8.15-p31 | |
Zimbra | =8.8.15-p32 | |
Zimbra | =8.8.15-p33 | |
Zimbra | =8.8.15-p34 | |
Zimbra | =8.8.15-p35 | |
Zimbra | =8.8.15-p37 | |
Zimbra | =8.8.15-p38 | |
Zimbra | =8.8.15-p40 | |
Zimbra | =8.8.15-p5 | |
Zimbra | =9.0.0 | |
Zimbra | =9.0.0-p0 | |
Zimbra | =9.0.0-p19 | |
Zimbra | =9.0.0-p23 | |
Zimbra | =9.0.0-p25 | |
Zimbra | =9.0.0-p26 | |
Zimbra | =9.0.0-p27 | |
Zimbra | =9.0.0-p28 | |
Zimbra | =9.0.0-p30 | |
Zimbra | =9.0.0-p31 | |
Zimbra | =9.0.0-p33 | |
Zimbra | =9.0.0-p4 | |
Zimbra | =9.0.0-p7 | |
Zimbra | =9.0.0-p7.1 | |
Zimbra | =10.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38750 has a severity rating of 7.5 (High).
CVE-2023-38750 allows internal JSP and XML files to be exposed in Zimbra Collaboration (ZCS) version 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2.
CVE-2023-38750 affects Zimbra Collaboration (ZCS) versions 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2.
Yes, the fix for CVE-2023-38750 is available in Zimbra Collaboration (ZCS) version 8.8.15 Patch 41, 9.0.0 Patch 34, and 10.0.2.