CVE-2019-9621

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows...

Basic Information

CVE State
PUBLISHED
Reserved Date
March 06, 2019
Published Date
April 30, 2019
Last Updated
July 30, 2025
Vendor
Zimbra
Product
Collaboration Suite
Description
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
Tags
cisa

CVSS Scores

CVSS v3.0

7.5 - HIGH

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2.0

5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Score

Score
91.64% (Percentile: 99.66%) as of 2025-07-29

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2025-07-07 17:45:23 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2025-07-07 17:45:14 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

zimbra_xxe_rce

Type: metasploit • Created: Unknown

Metasploit module for CVE-2019-9621

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Metasploit

  • Added to KEVIntel