10

CVE-2024-45519

Warnung
Exploit
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SynacorZimbra Collaboration Suite Version < 8.8.15
SynacorZimbra Collaboration Suite Version >= 10.0.0 < 10.0.9
SynacorZimbra Collaboration Suite Version8.8.15 Update-
SynacorZimbra Collaboration Suite Version8.8.15 Updatep1
SynacorZimbra Collaboration Suite Version8.8.15 Updatep10
SynacorZimbra Collaboration Suite Version8.8.15 Updatep11
SynacorZimbra Collaboration Suite Version8.8.15 Updatep12
SynacorZimbra Collaboration Suite Version8.8.15 Updatep13
SynacorZimbra Collaboration Suite Version8.8.15 Updatep14
SynacorZimbra Collaboration Suite Version8.8.15 Updatep15
SynacorZimbra Collaboration Suite Version8.8.15 Updatep16
SynacorZimbra Collaboration Suite Version8.8.15 Updatep17
SynacorZimbra Collaboration Suite Version8.8.15 Updatep18
SynacorZimbra Collaboration Suite Version8.8.15 Updatep19
SynacorZimbra Collaboration Suite Version8.8.15 Updatep2
SynacorZimbra Collaboration Suite Version8.8.15 Updatep20
SynacorZimbra Collaboration Suite Version8.8.15 Updatep21
SynacorZimbra Collaboration Suite Version8.8.15 Updatep22
SynacorZimbra Collaboration Suite Version8.8.15 Updatep23
SynacorZimbra Collaboration Suite Version8.8.15 Updatep24
SynacorZimbra Collaboration Suite Version8.8.15 Updatep25
SynacorZimbra Collaboration Suite Version8.8.15 Updatep26
SynacorZimbra Collaboration Suite Version8.8.15 Updatep27
SynacorZimbra Collaboration Suite Version8.8.15 Updatep28
SynacorZimbra Collaboration Suite Version8.8.15 Updatep29
SynacorZimbra Collaboration Suite Version8.8.15 Updatep3
SynacorZimbra Collaboration Suite Version8.8.15 Updatep30
SynacorZimbra Collaboration Suite Version8.8.15 Updatep31
SynacorZimbra Collaboration Suite Version8.8.15 Updatep31.1
SynacorZimbra Collaboration Suite Version8.8.15 Updatep32
SynacorZimbra Collaboration Suite Version8.8.15 Updatep33
SynacorZimbra Collaboration Suite Version8.8.15 Updatep34
SynacorZimbra Collaboration Suite Version8.8.15 Updatep35
SynacorZimbra Collaboration Suite Version8.8.15 Updatep36
SynacorZimbra Collaboration Suite Version8.8.15 Updatep37
SynacorZimbra Collaboration Suite Version8.8.15 Updatep38
SynacorZimbra Collaboration Suite Version8.8.15 Updatep39
SynacorZimbra Collaboration Suite Version8.8.15 Updatep4
SynacorZimbra Collaboration Suite Version8.8.15 Updatep40
SynacorZimbra Collaboration Suite Version8.8.15 Updatep41
SynacorZimbra Collaboration Suite Version8.8.15 Updatep42
SynacorZimbra Collaboration Suite Version8.8.15 Updatep43
SynacorZimbra Collaboration Suite Version8.8.15 Updatep44
SynacorZimbra Collaboration Suite Version8.8.15 Updatep45
SynacorZimbra Collaboration Suite Version8.8.15 Updatep5
SynacorZimbra Collaboration Suite Version8.8.15 Updatep6
SynacorZimbra Collaboration Suite Version8.8.15 Updatep7
SynacorZimbra Collaboration Suite Version8.8.15 Updatep8
SynacorZimbra Collaboration Suite Version8.8.15 Updatep9
SynacorZimbra Collaboration Suite Version9.0.0 Update-
SynacorZimbra Collaboration Suite Version9.0.0 Updatep1
SynacorZimbra Collaboration Suite Version9.0.0 Updatep10
SynacorZimbra Collaboration Suite Version9.0.0 Updatep11
SynacorZimbra Collaboration Suite Version9.0.0 Updatep12
SynacorZimbra Collaboration Suite Version9.0.0 Updatep13
SynacorZimbra Collaboration Suite Version9.0.0 Updatep14
SynacorZimbra Collaboration Suite Version9.0.0 Updatep15
SynacorZimbra Collaboration Suite Version9.0.0 Updatep16
SynacorZimbra Collaboration Suite Version9.0.0 Updatep17
SynacorZimbra Collaboration Suite Version9.0.0 Updatep18
SynacorZimbra Collaboration Suite Version9.0.0 Updatep19
SynacorZimbra Collaboration Suite Version9.0.0 Updatep2
SynacorZimbra Collaboration Suite Version9.0.0 Updatep20
SynacorZimbra Collaboration Suite Version9.0.0 Updatep21
SynacorZimbra Collaboration Suite Version9.0.0 Updatep22
SynacorZimbra Collaboration Suite Version9.0.0 Updatep23
SynacorZimbra Collaboration Suite Version9.0.0 Updatep24
SynacorZimbra Collaboration Suite Version9.0.0 Updatep24.1
SynacorZimbra Collaboration Suite Version9.0.0 Updatep25
SynacorZimbra Collaboration Suite Version9.0.0 Updatep26
SynacorZimbra Collaboration Suite Version9.0.0 Updatep27
SynacorZimbra Collaboration Suite Version9.0.0 Updatep28
SynacorZimbra Collaboration Suite Version9.0.0 Updatep29
SynacorZimbra Collaboration Suite Version9.0.0 Updatep3
SynacorZimbra Collaboration Suite Version9.0.0 Updatep30
SynacorZimbra Collaboration Suite Version9.0.0 Updatep31
SynacorZimbra Collaboration Suite Version9.0.0 Updatep32
SynacorZimbra Collaboration Suite Version9.0.0 Updatep33
SynacorZimbra Collaboration Suite Version9.0.0 Updatep34
SynacorZimbra Collaboration Suite Version9.0.0 Updatep35
SynacorZimbra Collaboration Suite Version9.0.0 Updatep36
SynacorZimbra Collaboration Suite Version9.0.0 Updatep37
SynacorZimbra Collaboration Suite Version9.0.0 Updatep38
SynacorZimbra Collaboration Suite Version9.0.0 Updatep39
SynacorZimbra Collaboration Suite Version9.0.0 Updatep4
SynacorZimbra Collaboration Suite Version9.0.0 Updatep40
SynacorZimbra Collaboration Suite Version9.0.0 Updatep5
SynacorZimbra Collaboration Suite Version9.0.0 Updatep6
SynacorZimbra Collaboration Suite Version9.0.0 Updatep7
SynacorZimbra Collaboration Suite Version9.0.0 Updatep8
SynacorZimbra Collaboration Suite Version9.0.0 Updatep9

03.10.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog

Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

Schwachstelle

Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.

Beschreibung

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.14% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cve@mitre.org 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.