CVE CVE

CVE-2024-45519

CISA Known Exploited Vulnerability (KEV)

Synacor Zimbra Collaboration Command Execution Vulnerability

October 3, 2024

October 24, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

Weakness Enumeration

CWE-ID CWE Name

CWE-284
Improper Access Control

Known Affected Software Configurations


cpe:2.3:a:zimbra:collaboration:10.0.4:*:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p42:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p35:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p41:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:10.0.2:*:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:10.0.3:*:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p34:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p37:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p33:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p35:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:10.0.0:*:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:10.0.1:*:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p40:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p24.1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p16:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p21:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p20:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p24:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p32:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p30:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p34:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.4:*:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p26:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p33:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.3:*:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p19:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p7.1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p0:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.2:*:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.0:beta1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p15:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p31:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p27:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p25:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p23:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:*:*:*:open_source:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p25:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p27:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p29:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p23:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p24:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p26:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p28:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p22:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p15:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p13:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:9.0.0:p14:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p20:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.15:p21:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p3:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p10:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p4:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p11:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p5:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p6:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p7:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p8:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p9:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p12:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p13:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p2:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.7.11:p14:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.12:p1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.12:p2:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.12:p3:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.12:p4:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.12:p5:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.12:p6:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.11:p1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.11:p2:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.11:p3:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.11:p4:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.11:p5:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.10:p5:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.10:p6:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.10:p7:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.10:p8:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.10:p1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.10:p2:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.10:p3:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.10:p4:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p7:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p4:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p8:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p5:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p3:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p2:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p6:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p9:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.9:p10:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.8:p10:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.8:p1:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.8:p2:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.8:p3:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.8:p9:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.8:p6:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.8:p5:*:*:*:*:*:*

cpe:2.3:a:zimbra:collaboration:8.8.8:p4:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined