CVE-2018-15131

An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enumeration is possible via inconsistent responses for specific types of authentication requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
synacorzimbra_collaboration_suite
8.7.0 ≤
𝑥
< 8.7.11
synacorzimbra_collaboration_suite
8.8.0 ≤
𝑥
< 8.8.8
synacorzimbra_collaboration_suite
8.6.0
synacorzimbra_collaboration_suite
8.6.0:p1
synacorzimbra_collaboration_suite
8.6.0:p10
synacorzimbra_collaboration_suite
8.6.0:p2
synacorzimbra_collaboration_suite
8.6.0:p3
synacorzimbra_collaboration_suite
8.6.0:p4
synacorzimbra_collaboration_suite
8.6.0:p5
synacorzimbra_collaboration_suite
8.6.0:p6
synacorzimbra_collaboration_suite
8.6.0:p8
synacorzimbra_collaboration_suite
8.6.0:p9
synacorzimbra_collaboration_suite
8.7.11
synacorzimbra_collaboration_suite
8.7.11:p1
synacorzimbra_collaboration_suite
8.7.11:p2
synacorzimbra_collaboration_suite
8.7.11:p3
synacorzimbra_collaboration_suite
8.7.11:p4
synacorzimbra_collaboration_suite
8.7.11:p5
synacorzimbra_collaboration_suite
8.8.8
synacorzimbra_collaboration_suite
8.8.8:p1
synacorzimbra_collaboration_suite
8.8.8:p2
synacorzimbra_collaboration_suite
8.8.8:p3
synacorzimbra_collaboration_suite
8.8.8:p4
synacorzimbra_collaboration_suite
8.8.8:p5
synacorzimbra_collaboration_suite
8.8.8:p6
synacorzimbra_collaboration_suite
8.8.8:p7
synacorzimbra_collaboration_suite
8.8.9
synacorzimbra_collaboration_suite
8.8.9:p1
synacorzimbra_collaboration_suite
8.8.9:p2
𝑥
= Vulnerable software versions