Lucene search

K
nvd[email protected]NVD:CVE-2022-37393
HistoryAug 16, 2022 - 8:15 p.m.

CVE-2022-37393

2022-08-1620:15:07
CWE-284
web.nvd.nist.gov
1

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

45.3%

Zimbra’s sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

Affected configurations

NVD
Node
zimbracollaborationMatch8.7.6
OR
zimbracollaborationMatch8.7.7
OR
zimbracollaborationMatch8.7.9
OR
zimbracollaborationMatch8.7.10
OR
zimbracollaborationMatch8.7.11-
OR
zimbracollaborationMatch8.7.11p1
OR
zimbracollaborationMatch8.7.11p10
OR
zimbracollaborationMatch8.7.11p11
OR
zimbracollaborationMatch8.7.11p12
OR
zimbracollaborationMatch8.7.11p13
OR
zimbracollaborationMatch8.7.11p14
OR
zimbracollaborationMatch8.7.11p15
OR
zimbracollaborationMatch8.7.11p2
OR
zimbracollaborationMatch8.7.11p3
OR
zimbracollaborationMatch8.7.11p4
OR
zimbracollaborationMatch8.7.11p5
OR
zimbracollaborationMatch8.7.11p6
OR
zimbracollaborationMatch8.7.11p7
OR
zimbracollaborationMatch8.7.11p8
OR
zimbracollaborationMatch8.7.11p9
OR
zimbracollaborationMatch8.8.0beta1
OR
zimbracollaborationMatch8.8.2
OR
zimbracollaborationMatch8.8.3
OR
zimbracollaborationMatch8.8.4
OR
zimbracollaborationMatch8.8.6
OR
zimbracollaborationMatch8.8.7
OR
zimbracollaborationMatch8.8.8-
OR
zimbracollaborationMatch8.8.8p1
OR
zimbracollaborationMatch8.8.8p3
OR
zimbracollaborationMatch8.8.8p4
OR
zimbracollaborationMatch8.8.8p7
OR
zimbracollaborationMatch8.8.9-
OR
zimbracollaborationMatch8.8.9p1
OR
zimbracollaborationMatch8.8.9p10
OR
zimbracollaborationMatch8.8.9p3
OR
zimbracollaborationMatch8.8.10-
OR
zimbracollaborationMatch8.8.10p8
OR
zimbracollaborationMatch8.8.11-
OR
zimbracollaborationMatch8.8.11p3
OR
zimbracollaborationMatch8.8.11p4
OR
zimbracollaborationMatch8.8.11p5
OR
zimbracollaborationMatch8.8.12-
OR
zimbracollaborationMatch8.8.12p3
OR
zimbracollaborationMatch8.8.12p4
OR
zimbracollaborationMatch8.8.15-
OR
zimbracollaborationMatch8.8.15p11
OR
zimbracollaborationMatch8.8.15p26
OR
zimbracollaborationMatch8.8.15p3
OR
zimbracollaborationMatch8.8.15p30
OR
zimbracollaborationMatch8.8.15p31
OR
zimbracollaborationMatch8.8.15p32
OR
zimbracollaborationMatch8.8.15p33
OR
zimbracollaborationMatch8.8.15p34
OR
zimbracollaborationMatch8.8.15p5
OR
zimbracollaborationMatch9.0.0p0
OR
zimbracollaborationMatch9.0.0p19
OR
zimbracollaborationMatch9.0.0p23
OR
zimbracollaborationMatch9.0.0p25
OR
zimbracollaborationMatch9.0.0p26
OR
zimbracollaborationMatch9.0.0p27
OR
zimbracollaborationMatch9.0.0p4
OR
zimbracollaborationMatch9.0.0p7
OR
zimbracollaborationMatch9.0.0p7.1

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

45.3%