CVE-2020-7796
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Zimbra email server versions before 8.8.15 Patch 7 have a flaw in the WebEx plugin that allows attackers to make the server connect to internal or external systems on their behalf, potentially exposing sensitive data or compromising internal infrastructure.
Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration Suite WebEx zimlet when JSP execution is enabled. Attackers can craft requests to the zimlet endpoint to force the server to make HTTP requests to arbitrary internal or external targets, bypassing network controls and potentially accessing restricted resources or metadata services.
The full analysis of this CVE is available in Portuguese →