Zimbra.Collaboration.Autodiscover.Servlet.XXE
Description
This indicates an attack attempt against an Information Disclosure vulnerability in Zimbra Collaboration Suite.
The vulnerabilities is due to an error in the application when handling a crafted http request. A remote attacker can exploit this to gain unauthorized access to sensitive information, via a crafted http request.
Affected Products
Zimbra Collaboration Suite v8.5 to v8.7.11
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://wiki.zimbra.com/wiki/Zimbra_Releases
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2020-08-06 | 15.901 | Sig Added |
2019-04-26 | 14.602 | Default_action:pass:drop |
2019-04-24 | 14.599 | Sig Added |
2019-04-17 | 14.596 |