Lucene search

K
nvd[email protected]NVD:CVE-2023-38750
HistoryJul 31, 2023 - 4:15 p.m.

CVE-2023-38750

2023-07-3116:15:10
web.nvd.nist.gov
7
zimbra collaboration
vulnerability
jsp
xml
exposure

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

47.0%

In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed.

Affected configurations

Nvd
Node
zimbrazimbraRange8.8.08.8.15
OR
zimbrazimbraMatch8.8.15p11
OR
zimbrazimbraMatch8.8.15p26
OR
zimbrazimbraMatch8.8.15p3
OR
zimbrazimbraMatch8.8.15p30
OR
zimbrazimbraMatch8.8.15p31
OR
zimbrazimbraMatch8.8.15p32
OR
zimbrazimbraMatch8.8.15p33
OR
zimbrazimbraMatch8.8.15p34
OR
zimbrazimbraMatch8.8.15p35
OR
zimbrazimbraMatch8.8.15p37
OR
zimbrazimbraMatch8.8.15p38
OR
zimbrazimbraMatch8.8.15p40
OR
zimbrazimbraMatch8.8.15p5
OR
zimbrazimbraMatch9.0.0
OR
zimbrazimbraMatch9.0.0p0
OR
zimbrazimbraMatch9.0.0p19
OR
zimbrazimbraMatch9.0.0p23
OR
zimbrazimbraMatch9.0.0p25
OR
zimbrazimbraMatch9.0.0p26
OR
zimbrazimbraMatch9.0.0p27
OR
zimbrazimbraMatch9.0.0p28
OR
zimbrazimbraMatch9.0.0p30
OR
zimbrazimbraMatch9.0.0p31
OR
zimbrazimbraMatch9.0.0p33
OR
zimbrazimbraMatch9.0.0p4
OR
zimbrazimbraMatch9.0.0p7
OR
zimbrazimbraMatch9.0.0p7.1
OR
zimbrazimbraMatch10.0.1
VendorProductVersionCPE
zimbrazimbra*cpe:2.3:a:zimbra:zimbra:*:*:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p11:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p26:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p3:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p30:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p31:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p32:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p33:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p34:*:*:*:*:*:*
zimbrazimbra8.8.15cpe:2.3:a:zimbra:zimbra:8.8.15:p35:*:*:*:*:*:*
Rows per page:
1-10 of 291

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

47.0%

Related for NVD:CVE-2023-38750