Zimbra.Collaboration.Autodiscover.Servlet.XXE
Description
This indicates an attack attempt against an Information Disclosure vulnerability in Zimbra Collaboration Suite.
The vulnerabilities is due to an error in the application when handling a crafted http request. A remote attacker can exploit this to gain unauthorized access to sensitive information, via a crafted http request.
Affected Products
Zimbra Collaboration Suite v8.5 to v8.7.11
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor. https://wiki.zimbra.com/wiki/Zimbra_Releases
Version Updates
Date | Version | Detail |
---|---|---|
2022-05-16 | 0.00320 |