CVE-2018-15131

EUVD-2018-7012
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enumeration is possible via inconsistent responses for specific types of authentication requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
synacorzimbra_collaboration_suite
8.7.0 ≤
𝑥
< 8.7.11
synacorzimbra_collaboration_suite
8.8.0 ≤
𝑥
< 8.8.8
synacorzimbra_collaboration_suite
8.6.0
synacorzimbra_collaboration_suite
8.6.0:p1
synacorzimbra_collaboration_suite
8.6.0:p10
synacorzimbra_collaboration_suite
8.6.0:p2
synacorzimbra_collaboration_suite
8.6.0:p3
synacorzimbra_collaboration_suite
8.6.0:p4
synacorzimbra_collaboration_suite
8.6.0:p5
synacorzimbra_collaboration_suite
8.6.0:p6
synacorzimbra_collaboration_suite
8.6.0:p8
synacorzimbra_collaboration_suite
8.6.0:p9
synacorzimbra_collaboration_suite
8.7.11
synacorzimbra_collaboration_suite
8.7.11:p1
synacorzimbra_collaboration_suite
8.7.11:p2
synacorzimbra_collaboration_suite
8.7.11:p3
synacorzimbra_collaboration_suite
8.7.11:p4
synacorzimbra_collaboration_suite
8.7.11:p5
synacorzimbra_collaboration_suite
8.8.8
synacorzimbra_collaboration_suite
8.8.8:p1
synacorzimbra_collaboration_suite
8.8.8:p2
synacorzimbra_collaboration_suite
8.8.8:p3
synacorzimbra_collaboration_suite
8.8.8:p4
synacorzimbra_collaboration_suite
8.8.8:p5
synacorzimbra_collaboration_suite
8.8.8:p6
synacorzimbra_collaboration_suite
8.8.8:p7
synacorzimbra_collaboration_suite
8.8.9
synacorzimbra_collaboration_suite
8.8.9:p1
synacorzimbra_collaboration_suite
8.8.9:p2
𝑥
= Vulnerable software versions