7.8

CVE-2022-37393

Exploit
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZimbraCollaboration Version8.7.6
ZimbraCollaboration Version8.7.7
ZimbraCollaboration Version8.7.9
ZimbraCollaboration Version8.7.10
ZimbraCollaboration Version8.7.11 Update-
ZimbraCollaboration Version8.7.11 Updatep1
ZimbraCollaboration Version8.7.11 Updatep10
ZimbraCollaboration Version8.7.11 Updatep11
ZimbraCollaboration Version8.7.11 Updatep12
ZimbraCollaboration Version8.7.11 Updatep13
ZimbraCollaboration Version8.7.11 Updatep14
ZimbraCollaboration Version8.7.11 Updatep15
ZimbraCollaboration Version8.7.11 Updatep2
ZimbraCollaboration Version8.7.11 Updatep3
ZimbraCollaboration Version8.7.11 Updatep4
ZimbraCollaboration Version8.7.11 Updatep5
ZimbraCollaboration Version8.7.11 Updatep6
ZimbraCollaboration Version8.7.11 Updatep7
ZimbraCollaboration Version8.7.11 Updatep8
ZimbraCollaboration Version8.7.11 Updatep9
ZimbraCollaboration Version8.8.0 Updatebeta1
ZimbraCollaboration Version8.8.2
ZimbraCollaboration Version8.8.3
ZimbraCollaboration Version8.8.4
ZimbraCollaboration Version8.8.6
ZimbraCollaboration Version8.8.7
ZimbraCollaboration Version8.8.8 Update-
ZimbraCollaboration Version8.8.8 Updatep1
ZimbraCollaboration Version8.8.8 Updatep3
ZimbraCollaboration Version8.8.8 Updatep4
ZimbraCollaboration Version8.8.8 Updatep7
ZimbraCollaboration Version8.8.9 Update-
ZimbraCollaboration Version8.8.9 Updatep1
ZimbraCollaboration Version8.8.9 Updatep10
ZimbraCollaboration Version8.8.9 Updatep3
ZimbraCollaboration Version8.8.10 Update-
ZimbraCollaboration Version8.8.10 Updatep8
ZimbraCollaboration Version8.8.11 Update-
ZimbraCollaboration Version8.8.11 Updatep3
ZimbraCollaboration Version8.8.11 Updatep4
ZimbraCollaboration Version8.8.11 Updatep5
ZimbraCollaboration Version8.8.12 Update-
ZimbraCollaboration Version8.8.12 Updatep3
ZimbraCollaboration Version8.8.12 Updatep4
ZimbraCollaboration Version8.8.15 Update-
ZimbraCollaboration Version8.8.15 Updatep11
ZimbraCollaboration Version8.8.15 Updatep26
ZimbraCollaboration Version8.8.15 Updatep3
ZimbraCollaboration Version8.8.15 Updatep30
ZimbraCollaboration Version8.8.15 Updatep31
ZimbraCollaboration Version8.8.15 Updatep32
ZimbraCollaboration Version8.8.15 Updatep33
ZimbraCollaboration Version8.8.15 Updatep34
ZimbraCollaboration Version8.8.15 Updatep5
ZimbraCollaboration Version9.0.0 Updatep0
ZimbraCollaboration Version9.0.0 Updatep19
ZimbraCollaboration Version9.0.0 Updatep23
ZimbraCollaboration Version9.0.0 Updatep25
ZimbraCollaboration Version9.0.0 Updatep26
ZimbraCollaboration Version9.0.0 Updatep27
ZimbraCollaboration Version9.0.0 Updatep4
ZimbraCollaboration Version9.0.0 Updatep7
ZimbraCollaboration Version9.0.0 Updatep7.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.12% 0.895
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.