VulnerabilityModified
CVE-2020-35123
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks.
MEDIUM 6.5EPSS 1.51%
Does this matter?
Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.
Description
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.51% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- zimbra/collaboration
- Source
- cve@mitre.org
References
- https://wiki.zimbra.com/wiki/Security_CenterProduct
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P17Release Notes, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P10Third Party Advisory, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
- https://wiki.zimbra.com/wiki/Security_CenterProduct
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P17Release Notes, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P10Third Party Advisory, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.