Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_AUTH_TOKEN token.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://osvdb.org/97290 | vdb entry |
http://www.securityfocus.com/bid/62407 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2013-09/0063.html | mailing list |