CVE-2019-9621
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
- Affected products
- Zimbra Collaboration Suite
- Synacor Zimbra Collaboration Suite
- < 8.6.0, 8.7.11, 8.8.9, 8.8.10, 8.8.11
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 81.0% (100th percentile)
- Weakness
- CWE-918
- NVD status
- Analyzed
- Published
- 2019-04-30
CVE-2019-9621 at NVD
11 known exploits for CVE-2019-9621
Proof-of-concept code and exploit modules indexed by Sploitus
ZimbraExploit
Zimbra Collaboration Suite ProxyServlet Server Side Request Forgery
Zimbra Collaboration Suite ProxyServlet Server Side Request Forgery
Zimbra Collaboration Suite ProxyServlet Server Side Request Forgery
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery Vulnerability
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery
Zimbra XML Injection / Server-Side Request Forgery
Exploit for Server-Side Request Forgery in Synacor Zimbra_Collaboration_Suite
Zimbra Collaboration - Autodiscover Servlet XXE and ProxyServlet SSRF (Metasploit)
Zimbra Collaboration Autodiscover Servlet XXE / ProxyServlet SSRF Exploit
Zimbra Collaboration Autodiscover Servlet XXE / ProxyServlet SSRF