vulnerability

Zimbra Collaboration: CVE-2022-37042: Authentication Bypass vulnerability.

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Aug 11, 2022
Added
Aug 18, 2022
Modified
Nov 21, 2025

Description

Zimbra collaboration suite (zcs) 8.8.15 and 9.0 has mboximport functionality that receives a zip archive and extracts files from it. by bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. note: this issue exists because of an incomplete fix for cve-2022-27925.

Solution

zimbra-collaboration-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.