7.8
CVE-2023-24032
- EPSS 0.96%
- Veröffentlicht 15.06.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:47:17
- Erkennungen
In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege escalation (LPE).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zimbra ≫ Collaboration Version 8.8.15 Update -
Zimbra ≫ Collaboration Version 8.8.15 Update p1
Zimbra ≫ Collaboration Version 8.8.15 Update p10
Zimbra ≫ Collaboration Version 8.8.15 Update p11
Zimbra ≫ Collaboration Version 8.8.15 Update p12
Zimbra ≫ Collaboration Version 8.8.15 Update p13
Zimbra ≫ Collaboration Version 8.8.15 Update p14
Zimbra ≫ Collaboration Version 8.8.15 Update p15
Zimbra ≫ Collaboration Version 8.8.15 Update p16
Zimbra ≫ Collaboration Version 8.8.15 Update p17
Zimbra ≫ Collaboration Version 8.8.15 Update p18
Zimbra ≫ Collaboration Version 8.8.15 Update p19
Zimbra ≫ Collaboration Version 8.8.15 Update p2
Zimbra ≫ Collaboration Version 8.8.15 Update p20
Zimbra ≫ Collaboration Version 8.8.15 Update p21
Zimbra ≫ Collaboration Version 8.8.15 Update p22
Zimbra ≫ Collaboration Version 8.8.15 Update p23
Zimbra ≫ Collaboration Version 8.8.15 Update p24
Zimbra ≫ Collaboration Version 8.8.15 Update p25
Zimbra ≫ Collaboration Version 8.8.15 Update p26
Zimbra ≫ Collaboration Version 8.8.15 Update p27
Zimbra ≫ Collaboration Version 8.8.15 Update p28
Zimbra ≫ Collaboration Version 8.8.15 Update p29
Zimbra ≫ Collaboration Version 8.8.15 Update p3
Zimbra ≫ Collaboration Version 8.8.15 Update p30
Zimbra ≫ Collaboration Version 8.8.15 Update p31
Zimbra ≫ Collaboration Version 8.8.15 Update p32
Zimbra ≫ Collaboration Version 8.8.15 Update p33
Zimbra ≫ Collaboration Version 8.8.15 Update p34
Zimbra ≫ Collaboration Version 8.8.15 Update p35
Zimbra ≫ Collaboration Version 8.8.15 Update p4
Zimbra ≫ Collaboration Version 8.8.15 Update p5
Zimbra ≫ Collaboration Version 8.8.15 Update p6
Zimbra ≫ Collaboration Version 8.8.15 Update p7
Zimbra ≫ Collaboration Version 8.8.15 Update p8
Zimbra ≫ Collaboration Version 8.8.15 Update p9
Zimbra ≫ Collaboration Version 9.0.0 Update -
Zimbra ≫ Collaboration Version 9.0.0 Update p0
Zimbra ≫ Collaboration Version 9.0.0 Update p1
Zimbra ≫ Collaboration Version 9.0.0 Update p10
Zimbra ≫ Collaboration Version 9.0.0 Update p11
Zimbra ≫ Collaboration Version 9.0.0 Update p12
Zimbra ≫ Collaboration Version 9.0.0 Update p13
Zimbra ≫ Collaboration Version 9.0.0 Update p14
Zimbra ≫ Collaboration Version 9.0.0 Update p15
Zimbra ≫ Collaboration Version 9.0.0 Update p19
Zimbra ≫ Collaboration Version 9.0.0 Update p2
Zimbra ≫ Collaboration Version 9.0.0 Update p23
Zimbra ≫ Collaboration Version 9.0.0 Update p25
Zimbra ≫ Collaboration Version 9.0.0 Update p26
Zimbra ≫ Collaboration Version 9.0.0 Update p27
Zimbra ≫ Collaboration Version 9.0.0 Update p3
Zimbra ≫ Collaboration Version 9.0.0 Update p33
Zimbra ≫ Collaboration Version 9.0.0 Update p4
Zimbra ≫ Collaboration Version 9.0.0 Update p5
Zimbra ≫ Collaboration Version 9.0.0 Update p6
Zimbra ≫ Collaboration Version 9.0.0 Update p7
Zimbra ≫ Collaboration Version 9.0.0 Update p7.1
Zimbra ≫ Collaboration Version 9.0.0 Update p8
Zimbra ≫ Collaboration Version 9.0.0 Update p9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.96% | 0.568 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://wiki.zimbra.com/wiki/Security_Center