7.8

CVE-2023-24032

In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege escalation (LPE).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zimbra ≫ Collaboration Version 8.8.15 Update -
Zimbra ≫ Collaboration Version 8.8.15 Update p1
Zimbra ≫ Collaboration Version 8.8.15 Update p10
Zimbra ≫ Collaboration Version 8.8.15 Update p11
Zimbra ≫ Collaboration Version 8.8.15 Update p12
Zimbra ≫ Collaboration Version 8.8.15 Update p13
Zimbra ≫ Collaboration Version 8.8.15 Update p14
Zimbra ≫ Collaboration Version 8.8.15 Update p15
Zimbra ≫ Collaboration Version 8.8.15 Update p16
Zimbra ≫ Collaboration Version 8.8.15 Update p17
Zimbra ≫ Collaboration Version 8.8.15 Update p18
Zimbra ≫ Collaboration Version 8.8.15 Update p19
Zimbra ≫ Collaboration Version 8.8.15 Update p2
Zimbra ≫ Collaboration Version 8.8.15 Update p20
Zimbra ≫ Collaboration Version 8.8.15 Update p21
Zimbra ≫ Collaboration Version 8.8.15 Update p22
Zimbra ≫ Collaboration Version 8.8.15 Update p23
Zimbra ≫ Collaboration Version 8.8.15 Update p24
Zimbra ≫ Collaboration Version 8.8.15 Update p25
Zimbra ≫ Collaboration Version 8.8.15 Update p26
Zimbra ≫ Collaboration Version 8.8.15 Update p27
Zimbra ≫ Collaboration Version 8.8.15 Update p28
Zimbra ≫ Collaboration Version 8.8.15 Update p29
Zimbra ≫ Collaboration Version 8.8.15 Update p3
Zimbra ≫ Collaboration Version 8.8.15 Update p30
Zimbra ≫ Collaboration Version 8.8.15 Update p31
Zimbra ≫ Collaboration Version 8.8.15 Update p32
Zimbra ≫ Collaboration Version 8.8.15 Update p33
Zimbra ≫ Collaboration Version 8.8.15 Update p34
Zimbra ≫ Collaboration Version 8.8.15 Update p35
Zimbra ≫ Collaboration Version 8.8.15 Update p4
Zimbra ≫ Collaboration Version 8.8.15 Update p5
Zimbra ≫ Collaboration Version 8.8.15 Update p6
Zimbra ≫ Collaboration Version 8.8.15 Update p7
Zimbra ≫ Collaboration Version 8.8.15 Update p8
Zimbra ≫ Collaboration Version 8.8.15 Update p9
Zimbra ≫ Collaboration Version 9.0.0 Update -
Zimbra ≫ Collaboration Version 9.0.0 Update p0
Zimbra ≫ Collaboration Version 9.0.0 Update p1
Zimbra ≫ Collaboration Version 9.0.0 Update p10
Zimbra ≫ Collaboration Version 9.0.0 Update p11
Zimbra ≫ Collaboration Version 9.0.0 Update p12
Zimbra ≫ Collaboration Version 9.0.0 Update p13
Zimbra ≫ Collaboration Version 9.0.0 Update p14
Zimbra ≫ Collaboration Version 9.0.0 Update p15
Zimbra ≫ Collaboration Version 9.0.0 Update p19
Zimbra ≫ Collaboration Version 9.0.0 Update p2
Zimbra ≫ Collaboration Version 9.0.0 Update p23
Zimbra ≫ Collaboration Version 9.0.0 Update p25
Zimbra ≫ Collaboration Version 9.0.0 Update p26
Zimbra ≫ Collaboration Version 9.0.0 Update p27
Zimbra ≫ Collaboration Version 9.0.0 Update p3
Zimbra ≫ Collaboration Version 9.0.0 Update p33
Zimbra ≫ Collaboration Version 9.0.0 Update p4
Zimbra ≫ Collaboration Version 9.0.0 Update p5
Zimbra ≫ Collaboration Version 9.0.0 Update p6
Zimbra ≫ Collaboration Version 9.0.0 Update p7
Zimbra ≫ Collaboration Version 9.0.0 Update p7.1
Zimbra ≫ Collaboration Version 9.0.0 Update p8
Zimbra ≫ Collaboration Version 9.0.0 Update p9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.96% 0.568
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
Vendor Advisory
https://wiki.zimbra.com/wiki/Security_Center
Patch
Release Notes