CISA Known Exploited Vulnerability

CVE-2019-9670

Synacor · Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

Date added
BOD 22-01 due date
CWE CWE-611
Ransomware Unknown

CISA description

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

Required action

Apply updates per vendor instructions.