CVE-2020-10194
Estado: ModificadaMedia (6.5)—
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.21%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-862
Referencias
- https://github.com/Zimbra/zm-mailbox/commit/1df440e0efa624d1772a05fb6d397d9beb4bda1e
- https://github.com/Zimbra/zm-mailbox/compare/8.8.15.p7...8.8.15.p8
- https://github.com/Zimbra/zm-mailbox/pull/1020
- https://github.com/Zimbra/zm-mailbox/commit/1df440e0efa624d1772a05fb6d397d9beb4bda1e
- https://github.com/Zimbra/zm-mailbox/compare/8.8.15.p7...8.8.15.p8
- https://github.com/Zimbra/zm-mailbox/pull/1020
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-10194",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-03-20T21:15:17.047",
"references": [
{
"url": "https://github.com/Zimbra/zm-mailbox/commit/1df440e0efa624d1772a05fb6d397d9beb4bda1e",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/Zimbra/zm-mailbox/compare/8.8.15.p7...8.8.15.p8",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/Zimbra/zm-mailbox/pull/1020",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/Zimbra/zm-mailbox/commit/1df440e0efa624d1772a05fb6d397d9beb4bda1e",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/Zimbra/zm-mailbox/compare/8.8.15.p7...8.8.15.p8",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/Zimbra/zm-mailbox/pull/1020",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request."
},
{
"lang": "es",
"value": "El archivo cs/service/account/AutoCompleteGal.java en zm-mailbox versiones anteriores a 8.8.15.p8, permite a usuarios autenticados solicitar cualquier cuenta GAL. Esto difiere del comportamiento previsto en el cual el dominio del usuario autenticado debe coincidir con el dominio de la cuenta galsync en la petición."
}
],
"lastModified": "2026-06-17T02:47:28.550",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8648A11D-E488-4EC5-9FA4-CBFB9D0651C5",
"versionEndExcluding": "8.8.15"
},
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:8.8.15:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "856F6E8C-F0BA-46AE-9398-8234DEBF27E5"
},
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "662E1C04-8CE4-477E-B568-319F295FAD11"
},
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD6F9BBA-98C4-4BD2-9AC2-E64D3DA0778E"
},
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "26DB5205-FDC1-4081-A09C-E8669F79BC2B"
},
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0584A545-FCA2-4EA8-986E-823A381BFB5A"
},
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4308E79A-EAAF-4E94-A975-DE3F3065B5A3"
},
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "398804EF-6EA6-4D60-8E82-36D213BA09E5"
},
{
"criteria": "cpe:2.3:a:zimbra:zm-mailbox:8.8.15:patch7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9CA03331-6A35-4042-986A-0C751FD9454B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}