Product: Zimbra Collaboration Suite
Vendor: VMWare
Vulnerable Version: 6.0.16 and probably prior
Tested Version: 6.0.16
Vendor Notification: 09/03/2013
Public Disclosure: 09/13/2013
Vulnerability Type: Authentication Bypass by Capture-replay (CWE-294)
CVE: CVE-2013-5119
Discovered and Provided By: Brian Warehime (Aplura LLC)

----------------------------------------------------------------------

Advisory Details:

A vulnerability exists in Zimbra Collaboration Suite (ZCS) which can be 
exploited to bypass authentication by replaying a captured session token. A 
remote attacker can sniff network traffic and obtain an authorized user's 
session token and modify the token on the attacker's machine to replay the 
token and successfully log in. If an attacker can capture the ZM_AUTH_TOKEN 
after a user has successfully logged in, the attacker can then create a new 
ZM_AUTH_TOKEN with the same information and log in, even after the other user 
logs out. 

--------------------------------------------------------------------------------------------------

Solution:

Upgrade to the latest version of ZCS.

Reply via email to