Honista APK

Cve20207796 Zimbra Collaboration Suite Full ((new)) Official

A successful exploit can lead to serious consequences, including:

In some scenarios, it may be possible to steal login credentials or inject malware through chained exploits. Current Threat Status cve20207796 zimbra collaboration suite full

CVE-2020-7796 is a server-side request forgery (SSRF) vulnerability in the Zimbra Collaboration Suite (ZCS) . It allows unauthenticated remote attackers to force the server to make HTTP requests to arbitrary internal or external hosts, effectively using the server as a proxy to bypass firewalls or access sensitive internal data. Vulnerability Details CVE ID: CVE-2020-7796 CVSS Score: 9.8 (Critical) Vulnerability Type: SSRF (CWE-918) A successful exploit can lead to serious consequences,

Upgrade to Zimbra Collaboration 8.8.15 Patch 7 or later . This version contains the necessary security fixes for this SSRF flaw. Vulnerability Details CVE ID: CVE-2020-7796 CVSS Score: 9

The vulnerability is specifically linked to the WebEx Zimlet ( com_zimbra_webex ) when the Zimlet JSP functionality is enabled.

Implement network-level restrictions to limit the Zimbra server’s outbound connections only to trusted destinations.

Scroll to Top