SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-35123

In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks.

MEDIUM 6.5EPSS 1.51%

Does this matter?

Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.

Description

In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.51% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
zimbra/collaboration
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.