CVE-2019-9621 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Zimbra Collaboration Suite versions prior to 8.6 patch 13, 8.7.11 patch 10, and 8.8.11 patch 3, specifically through the ProxyServlet component. This vulnerability carries a high CVSS score of 7.5, indicating a severe risk with a network-based attack vector requiring no user interaction, potentially leading to unauthorized information disclosure. It is actively exploited in the wild, listed in CISA's KEV catalog, and has publicly available exploit modules in Metasploit and Nuclei templates, as well as mentions on ExploitDB. The high EPSS score and community discussion further underscore its significant threat and active attention from security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.0CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | ||
>= 8.7.0, < 8.7.11CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | ||
>= 8.8.0, < 8.8.9CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | ||
8.6.0CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.6.0:-:*:*:*:*:*:* | ||
8.6.0CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.6.0:patch1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.