Vulnerability Description
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enumeration is possible via inconsistent responses for specific types of authentication requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synacor | Zimbra Collaboration Suite | >= 8.7.0, < 8.7.11 |
Related Weaknesses (CWE)
References
- https://bugzilla.zimbra.com/show_bug.cgi?id=109012ExploitIssue TrackingThird Party Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesVendor Advisory
- https://bugzilla.zimbra.com/show_bug.cgi?id=109012ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2018-15131?
CVE-2018-15131 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enume...
How severe is CVE-2018-15131?
CVE-2018-15131 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-15131?
Check the references section above for vendor advisories and patch information. Affected products include: Synacor Zimbra Collaboration Suite.