Added |
CVSS V3.1 |
|
NIST AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
Added |
CVSS V2 |
|
NIST (AV:N/AC:M/Au:N/C:N/I:P/A:N)
|
Added |
CWE |
|
NIST CWE-79
|
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:* versions from (including) 8.8 up to (excluding) 8.8.15
*cpe:2.3:a:zimbra:collaboration:8.8.15:-:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p1:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p10:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p11:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p12:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p13:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p14:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p15:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p16:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p17:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p18:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p19:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p2:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p20:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p21:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p22:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p23:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p24:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p25:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p26:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p27:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p28:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p29:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p3:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p4:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p5:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p6:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p7:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p8:*:*:*:*:*:*
*cpe:2.3:a:zimbra:collaboration:8.8.15:p9:*:*:*:*:*:*
|
Changed |
Reference Type |
https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vulnerability-in-zimbra-8-8-15/ No Types Assigned
|
https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vulnerability-in-zimbra-8-8-15/ Vendor Advisory
|
Changed |
Reference Type |
https://wiki.zimbra.com/wiki/Security_Center No Types Assigned
|
https://wiki.zimbra.com/wiki/Security_Center Vendor Advisory
|
Changed |
Reference Type |
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30 No Types Assigned
|
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P30 Release Notes, Vendor Advisory
|
Changed |
Reference Type |
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories No Types Assigned
|
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
|
Changed |
Reference Type |
https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/ No Types Assigned
|
https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/ Exploit, Third Party Advisory
|
Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism
|