Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/95917 | vdb entry |
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.7.0 | release notes |
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | vendor advisory |