CRITICAL
CVE-2024-45519
CVSS
9.8
KEV
Description
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Summary dbcve.org
The postjournal service in Zimbra Collaboration contains a command injection vulnerability allowing unauthenticated attackers to execute arbitrary commands on affected systems. The flaw affects multiple versions across ZCS 8.8.15, 9.x, 10.x, and 10.1.x prior to their respective patched releases.
Mitigation
Upgrade Zimbra Collaboration to version 8.8.15 Patch 46, 9.0.0 Patch 41, 10.0.9, or 10.1.1 or later to remediate this vulnerability.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
99.91%
Probability of exploitation in next 30 days
100th percentile
References
https://wiki.zimbra.com/wiki/Security_Center
Release Notes
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes
Release Notes
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes
Release Notes
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46#Security_Fixes
Release Notes
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes
Release Notes
https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
Not Applicable
https://blog.projectdiscovery.io/zimbra-remote-code-execution/
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-45519
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.