CVE-2020-7796
9.5 CISA KEVSynacor · Zimbra Collaboration Suite
A Server-Side Request Forgery (SSRF) vulnerability in the Zimbra Collaboration Suite WebEx zimlet allows unauthenticated remote attackers to perform unauthorized requests to internal network resources.
Executive summary
This critical SSRF vulnerability in Zimbra Collaboration Suite is actively exploited in the wild and requires immediate patching to prevent unauthorized access to internal services.
Vulnerability
This vulnerability occurs when the WebEx zimlet is installed and the JSP functionality is enabled, allowing an unauthenticated attacker to force the server to issue HTTP requests to arbitrary destinations. This bypasses network segmentation by leveraging the server as a proxy to reach restricted internal or external services.
Business impact
The CVSS score of 9.5 indicates a critical risk to organizational infrastructure. Successful exploitation allows attackers to bypass perimeter firewalls to interact with internal systems that are otherwise inaccessible from the public internet. This could lead to full data exfiltration, compromise of internal administrative interfaces, or the potential for lateral movement within the network.
Remediation
Immediate Action: Upgrade Zimbra Collaboration Suite to version 8.8.15 Patch 7 or later immediately to resolve the vulnerability.
Proactive Monitoring: Review web server access logs for anomalous outgoing requests originating from the Zimbra server, particularly those directed toward internal IP addresses or sensitive local services.
Compensating Controls: If immediate patching is not feasible, disable the WebEx zimlet and associated JSP functionality to eliminate the attack vector. Deploy a Web Application Firewall (WAF) with rules configured to block suspicious outbound requests or crafted URL parameters targeting the zimlet endpoints.
Exploitation status
Public Exploit Available: Yes (Nuclei detection templates exist).
Analyst recommendation
The active exploitation of this vulnerability in the wild presents an immediate and severe threat to any organization running the affected Zimbra Collaboration Suite versions. Security teams must ensure the patch is applied across all instances without delay. If the patch cannot be deployed immediately, isolating the affected system from the network or disabling the vulnerable WebEx zimlet is necessary to prevent exploitation.