CVE-2025-25065

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CISA-ADPADP
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
synacorzimbra_collaboration_suite
𝑥
< 9.0.0
synacorzimbra_collaboration_suite
10.0.0 ≤
𝑥
< 10.0.12
synacorzimbra_collaboration_suite
10.1.0 ≤
𝑥
< 10.1.4
synacorzimbra_collaboration_suite
9.0.0
synacorzimbra_collaboration_suite
9.0.0:p1
synacorzimbra_collaboration_suite
9.0.0:p10
synacorzimbra_collaboration_suite
9.0.0:p11
synacorzimbra_collaboration_suite
9.0.0:p12
synacorzimbra_collaboration_suite
9.0.0:p13
synacorzimbra_collaboration_suite
9.0.0:p14
synacorzimbra_collaboration_suite
9.0.0:p15
synacorzimbra_collaboration_suite
9.0.0:p16
synacorzimbra_collaboration_suite
9.0.0:p17
synacorzimbra_collaboration_suite
9.0.0:p18
synacorzimbra_collaboration_suite
9.0.0:p19
synacorzimbra_collaboration_suite
9.0.0:p2
synacorzimbra_collaboration_suite
9.0.0:p20
synacorzimbra_collaboration_suite
9.0.0:p21
synacorzimbra_collaboration_suite
9.0.0:p22
synacorzimbra_collaboration_suite
9.0.0:p23
synacorzimbra_collaboration_suite
9.0.0:p24
synacorzimbra_collaboration_suite
9.0.0:p24.1
synacorzimbra_collaboration_suite
9.0.0:p25
synacorzimbra_collaboration_suite
9.0.0:p26
synacorzimbra_collaboration_suite
9.0.0:p27
synacorzimbra_collaboration_suite
9.0.0:p28
synacorzimbra_collaboration_suite
9.0.0:p29
synacorzimbra_collaboration_suite
9.0.0:p3
synacorzimbra_collaboration_suite
9.0.0:p30
synacorzimbra_collaboration_suite
9.0.0:p31
synacorzimbra_collaboration_suite
9.0.0:p32
synacorzimbra_collaboration_suite
9.0.0:p33
synacorzimbra_collaboration_suite
9.0.0:p34
synacorzimbra_collaboration_suite
9.0.0:p35
synacorzimbra_collaboration_suite
9.0.0:p36
synacorzimbra_collaboration_suite
9.0.0:p37
synacorzimbra_collaboration_suite
9.0.0:p38
synacorzimbra_collaboration_suite
9.0.0:p39
synacorzimbra_collaboration_suite
9.0.0:p4
synacorzimbra_collaboration_suite
9.0.0:p40
synacorzimbra_collaboration_suite
9.0.0:p41
synacorzimbra_collaboration_suite
9.0.0:p42
synacorzimbra_collaboration_suite
9.0.0:p5
synacorzimbra_collaboration_suite
9.0.0:p6
synacorzimbra_collaboration_suite
9.0.0:p7
synacorzimbra_collaboration_suite
9.0.0:p8
synacorzimbra_collaboration_suite
9.0.0:p9
𝑥
= Vulnerable software versions