- Description
- An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- zimbra_collaboration_suite
CVSS 3.1
- Type
- Secondary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
- Exploit added on
- Oct 7, 2025
- Exploit action due
- Oct 28, 2025
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-79
- Hype score
- Not currently trending
A zero-day flaw (CVE-2025-27915) in Zimbra was used to target Brazil’s military via malicious ICS/calendar files. (The Hacker 😮 Why it’s relevant: If your business uses collaboration tools, even something as innocuous as a calendar inv it could be an entry point. 🛡 Yo
@BGMloop
7 Nov 2025
29 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
⚠️ XSS in Zimbra (CVE-2025-27915) lets JS run via an email with a malicious .ics — exploit published Sep 30; used in the wild vs Brazil’s military before Jan 27 patch. #Zimbra #StrikeReadyLabs ➡️ https://t.co/tJTVdqpKe2 https://t.co/s3YiDVeQUv
@leonov_av
26 Oct 2025
81 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
💥 El CVE-2025-27915 ha puesto a Zimbra bajo ataque. Miles de empresas están en riesgo por una vulnerabilidad crítica. 🔐 Aprende cómo proteger tu sistema antes de que sea tarde: actualiza, refuerza y monitoriza. 👉 Mantente informado y lleva tu seguridad al siguiente ni
@MMarcoSeguridad
23 Oct 2025
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-27915
@transilienceai
19 Oct 2025
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚔️ Hackers atacaron al ejército de #Brasil explotando una falla crítica en #Zimbra (CVE-2025-27915) mediante archivos ICS maliciosos 📷El fallo permitió ejecutar código oculto y robar correos y credenciales. 🔗 https://t.co/DcDURQOby2 https://t.co/skbEbedKhC
@ojo_cibernetico
18 Oct 2025
118 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚔️ Hackers atacaron al ejército de #Brasil explotando una falla crítica en #Zimbra (CVE-2025-27915) mediante archivos ICS maliciosos 📅💻 El fallo permitió ejecutar código oculto y robar correos y credenciales. 🔗 https://t.co/jhoqF7Lq99 https://t.co/hehwOHh71k
@ojo_cibernetico
18 Oct 2025
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 El ataque a Zimbra (CVE-2025-27915) nos deja una lección clara: nadie está a salvo si no actualiza a tiempo. 🔧 Los fallos en correo empresarial son una de las puertas más usadas por los atacantes. 👉 Mantén tus sistemas al día y protege tus datos. 💬 ¿Tu empres
@MMarcoSeguridad
16 Oct 2025
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Attackers Exploit Zimbra Zero-Day via ICS Calendar File https://t.co/d2s9wRlT7m A state-linked actor masquerading as the Libyan Navy delivered a malicious ICS file exploiting an XSS flaw (CVE-2025-27915) in Zimbra’s web client to steal credentials, emails, manipulate
@Huntio
13 Oct 2025
3059 Impressions
11 Retweets
27 Likes
8 Bookmarks
0 Replies
0 Quotes
زيمبرا — استـ ـغلال CVE-2025-27915 يستـ ـهدف الجيش البرازيلي التفاصيل .. https://t.co/1np05Ei4nE #مركز_الأمن_السيبراني_للابحاث_والدراسات https://t.co/8lriD7uV1r
@ccforrs
12 Oct 2025
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ Cyber Threat Digest – 2025-10-09 KEV: CVE-2025-27915 — Synacor Zimbra Collaboration Suite NVD: CVE-2025-11476 — vulnerability was identified in News: Azure outage blocks access to Microsoft… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv
@dpharristech
9 Oct 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Una vulnerabilidad Zero-Day pone en riesgo a Zimbra: CVE-2025-27915 https://t.co/LUZYJrfInr #Internet #Noticia #Tecnología #CiberSeguridad #web #Vulnerabilidad vía @unaaldia https://t.co/nwwnijYIhJ
@Securizame
9 Oct 2025
266 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
New Post: Vulnerabilidad Zero-Day pone en riesgo a Zimbra | CVE-2025-27915 https://t.co/DuPMELFNbs
@hualkana
8 Oct 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Zimbra bajo ataque #ZeroDay (CVE-2025-27915) — se están robando correos y datos en empresas de todo el mundo. Si usas Zimbra, parchea YA y revisa 💼 En @MMarcoSeguridad y @Ciberseguridad24h ayudamos a prevenir ataques y cumplir el #RGPD. 🌐 https://t.co/liiwnqVm89 h
@MMarcoSeguridad
8 Oct 2025
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ Cyber Threat Digest – 2025-10-08 KEV: CVE-2025-27915 — Synacor Zimbra Collaboration Suite NVD: CVE-2021-22291 — Improper Neutralization of Input News: Salesforce refuses to pay ransom over… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv
@dpharristech
8 Oct 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
csirt_it: ‼ #Zimbra: rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2025-27915 - già sanata dal vendor – relativa a #ZCS (Zimbra Collaboration Suite) Rischio: 🟠 🔗 https://t.co/u4OCBze842 ⚠ Importante aggiornare i prodotti interess… https://t.co
@Vulcanux_
8 Oct 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-27915 #Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability https://t.co/S6C2XShLlb
@ScyScan
7 Oct 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
هجوم إلكتروني يستهدف مستخدمي Zimbra عبر ملفات التقويم! يستغل المهاجمون ثغرة يوم الصفر (CVE-2025-27915) في نظام Zimbra من خلال ملفات iCalendar (.ICS) تحتوي على تعليمات JavaScript خ
@ChbibAnas
7 Oct 2025
13 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🛡️ We added Synacor Zimbra Collaboration Suite vulnerability CVE-2025-27915 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/f3UouEQBA3
@CISACyber
7 Oct 2025
3677 Impressions
9 Retweets
18 Likes
2 Bookmarks
0 Replies
0 Quotes
⚠️Vulnerabilidad en Zimbra ❗CVE-2025-27915 ➡️Más info: https://t.co/2Jq833GNf8 https://t.co/NGdajzhVql
@CERTpy
7 Oct 2025
106 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔓 تم استغلال ثغرة Zero-Day في Zimbra (CVE-2025-27915) لاستهداف البرازيل عبر ملفات ICS خبيثة، تُنفّذ تعليمات جافاسكريبت ضمن جلسات البريد الإلكتروني. #Zimbra #ThreatIntel #أمن_معل
@f16roo
6 Oct 2025
6 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
💥 hackers broke Zimbra Collaboration SuiteUsing Zero-Day Vulnerability Cve-2025-27915 through files Icalendar (.ICS). This allowed them introduce harmful javascript, steal letters, logins, contacts and transfer data to third -party addresses. Company Strikeready discovered an
@Hack_Your_Mom
6 Oct 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CORTEX Protocol Alert: Zimbra zero-day (CVE-2025-27915) exploited via weaponized iCalendar files. Attackers hijack sessions + steal emails. Patch immediately. CORTEX: revoke sessions, block .ICS, audit rules. https://t.co/gSEqw07Yth
@the_c_protocol
6 Oct 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#exploit #AppSec #Threat_Research 1⃣ Zimbra Exploit Analysis (CVE-2025-27915) https://t.co/8ovnzHtvXB // These exploits take advantage of .ics files to breach vulnerable systems 2⃣ Notepad++ DLL Hijacking (CVE-2025-56383) https://t.co/RGih3h81ws // If the threat actor has t
@ksg93rd
6 Oct 2025
45 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
A security vulnerability, identified as CVE-2025-27915, was discovered in the Zimbra Collaboration Suite (ZCS) and exploited in zero-day attacks in January 2025. This flaw stemmed from insufficient sanitization of HTML content in iCalendar (.ICS) files. The zero-day https://t.co/
@CTIAcademy
6 Oct 2025
207 Impressions
2 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
Zimbra zero-day (CVE-2025-27915) exploited Brazilian military via malicious ICS files (XSS). Patch released! 🛡️ https://t.co/Re1lUypbC7 #Zimbra #ZeroDay #CyberSecurity #BrazilianMilitary #XSS
@0xT3chn0m4nc3r
6 Oct 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
📌 تم استغلال ثغرة أمنية في Zimbra Collaboration لشن هجمات إلكترونية على الجيش البرازيلي باستخدام ملفات ICS خبيثة. تم تصنيف الثغرة، CVE-2025-27915، على أنها XSS مخزنة نتيجة
@Cybercachear
6 Oct 2025
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A “harmless” ICS calendar file exploited Zimbra’s XSS zero-day flaw (CVE-2025-27915) — turning an invite into a full data stealer. Target: Brazil’s military. The script waited 72 hours before exfiltrating credentials. Read → https://t.co/cMtaf1a8lN
@TheHackersNews
6 Oct 2025
16316 Impressions
45 Retweets
110 Likes
32 Bookmarks
5 Replies
2 Quotes
Zimbraの脆弱性CVE-2025-27915がゼロデイ攻撃に悪用される https://t.co/rWHBqFKQsv #Security #セキュリティー #ニュース
@SecureShield_
6 Oct 2025
89 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Zero-day flaw CVE-2025-27915 in Zimbra Collaboration Suite exploited via malicious iCalendar files enables JavaScript payload delivery, targeting military orgs. Attribution hints at Russian and Belarusian groups. #ZimbraFlaw #ICSattack #Belarus https://t.co/K9a9G9cDeo
@TweetThreatNews
5 Oct 2025
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Zimbra Collaboration Suite has patched critical vulnerabilities, including XSS, SQLi, and SSRF. Important to apply updates to maintain security. CVE-2025-27915, CVE-2025-25064, CVE-2025-25065. 🔒 #Zimbra #DataProtection #USA link: https://t.co/fFVt5BVFdz https://t.co/zjX96qTX5y
@TweetThreatNews
20 Mar 2025
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7F7A8D86-7352-45D1-A809-D19FCC4A4ED0",
"versionEndExcluding": "10.0.13",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CD5597BA-6D2C-4E3A-AA67-0F29DA04CA76",
"versionEndExcluding": "10.1.5",
"versionStartIncluding": "10.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:-:*:*:*:*:*:*",
"matchCriteriaId": "32AFCE22-5ADA-4FF7-A165-5EC12B325DEF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p1:*:*:*:*:*:*",
"matchCriteriaId": "D3577FE6-F1F4-4555-8D27-84D6DE731EA3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p10:*:*:*:*:*:*",
"matchCriteriaId": "931BD98E-1A5F-4634-945B-BDD7D2FAA8B0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p11:*:*:*:*:*:*",
"matchCriteriaId": "2E7C0A57-A887-4D29-B601-4275313F46B3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p12:*:*:*:*:*:*",
"matchCriteriaId": "B7248B91-D136-4DD5-A631-737E4C220A02",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p13:*:*:*:*:*:*",
"matchCriteriaId": "494F6FD4-36ED-4E40-8336-7F077FA80FA8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p14:*:*:*:*:*:*",
"matchCriteriaId": "9DF8C0CE-A71D-4BB1-83FB-1EA5ED77E0C9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p15:*:*:*:*:*:*",
"matchCriteriaId": "E0648498-2EE5-4B68-8360-ED5914285356",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p16:*:*:*:*:*:*",
"matchCriteriaId": "24282FF8-548B-415B-95CA-1EFD404D21D3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p17:*:*:*:*:*:*",
"matchCriteriaId": "ACFDF2D9-ED72-4969-AA3B-E8D48CB1922D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p18:*:*:*:*:*:*",
"matchCriteriaId": "2B7D0A8B-7A72-4C1A-85F2-BE336CA47E0B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p19:*:*:*:*:*:*",
"matchCriteriaId": "019AFC34-289E-4A01-B08B-A5807F7F909A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p2:*:*:*:*:*:*",
"matchCriteriaId": "7E7B3976-DA6F-4285-93E6-2328006F7F4D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p20:*:*:*:*:*:*",
"matchCriteriaId": "062E586F-0E02-45A6-93AD-895048FC2D4C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p21:*:*:*:*:*:*",
"matchCriteriaId": "3EE37BEE-4BDB-4E62-8DE3-98CF74DFBE01",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p22:*:*:*:*:*:*",
"matchCriteriaId": "ADF51BCA-37DD-4642-B201-74A6D1A545FF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p23:*:*:*:*:*:*",
"matchCriteriaId": "39611F3D-A898-4C35-8915-3334CDFB78E5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p24:*:*:*:*:*:*",
"matchCriteriaId": "40AB56B7-7222-4C44-A271-45DFE3673F72",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p24.1:*:*:*:*:*:*",
"matchCriteriaId": "2AE8F501-4528-4F15-AE50-D4F11FB462DE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p25:*:*:*:*:*:*",
"matchCriteriaId": "AB9E054B-7790-4E74-A771-40BF6EC71610",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p26:*:*:*:*:*:*",
"matchCriteriaId": "DD924E57-C77B-430B-A615-537BB39CEA9C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p27:*:*:*:*:*:*",
"matchCriteriaId": "F43F4AC0-7C82-4CF4-B0C7-3A4C567BC985",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p28:*:*:*:*:*:*",
"matchCriteriaId": "7991F602-41D7-4377-B888-D66A467EAD67",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p29:*:*:*:*:*:*",
"matchCriteriaId": "2193FCA2-1AE3-497D-B0ED-5B89727410E3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p3:*:*:*:*:*:*",
"matchCriteriaId": "FA310AFA-492D-4A6C-A7F6-740E82CB6E57",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p30:*:*:*:*:*:*",
"matchCriteriaId": "FF95618B-0BFB-403C-83BE-C97879FC866D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p31:*:*:*:*:*:*",
"matchCriteriaId": "A82346A9-9CC2-4B91-BA2F-A815AAA92A7F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p32:*:*:*:*:*:*",
"matchCriteriaId": "2E800348-E139-418D-910B-7B3A9E1E721C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p33:*:*:*:*:*:*",
"matchCriteriaId": "C7DE1A7E-573B-42F3-B0A4-D2E676954FE0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p34:*:*:*:*:*:*",
"matchCriteriaId": "E60BC1D0-8552-4E6B-B2C5-96038448C238",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p35:*:*:*:*:*:*",
"matchCriteriaId": "3924251E-13B0-420E-8080-D3312C3D54AF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p36:*:*:*:*:*:*",
"matchCriteriaId": "AEBE75F9-A494-4C78-927A-EA564BDCCE0B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p37:*:*:*:*:*:*",
"matchCriteriaId": "900BECBA-7FDB-4E35-9603-29706FB87BD2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p38:*:*:*:*:*:*",
"matchCriteriaId": "5024FD58-A3ED-43B1-83EF-F4570C2573BA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p39:*:*:*:*:*:*",
"matchCriteriaId": "3CC9D046-4EB4-4608-8AB7-B60AC330A770",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p4:*:*:*:*:*:*",
"matchCriteriaId": "2AF337B5-B296-449B-8848-7636EC7C46C5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p40:*:*:*:*:*:*",
"matchCriteriaId": "A4535EC5-74D5-41E8-95F1-5C033ADB043E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p41:*:*:*:*:*:*",
"matchCriteriaId": "408E1BFD-16AA-458C-B040-04870522FEBD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p42:*:*:*:*:*:*",
"matchCriteriaId": "205B2CDC-6423-4FD9-9FD0-847ADEB64003",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p43:*:*:*:*:*:*",
"matchCriteriaId": "CAE21C69-F080-4CE2-A39E-BF3509FB2005",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p5:*:*:*:*:*:*",
"matchCriteriaId": "52232ACA-C158-48C8-A0DB-7689040CB8FB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p6:*:*:*:*:*:*",
"matchCriteriaId": "3B4D0040-86D0-46C3-8A9A-3DD12138B9ED",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p7:*:*:*:*:*:*",
"matchCriteriaId": "D2BB9BC7-078D-4E08-88E4-9432D74CA9BA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p8:*:*:*:*:*:*",
"matchCriteriaId": "F04D4B77-D386-4BC8-8169-9846693F6F11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p9:*:*:*:*:*:*",
"matchCriteriaId": "992370FA-F171-4FB3-9C1C-58AC37038CE4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]