Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in the Admin Console. An unauthenticated remote attacker can send specially crafted GET requests that trigger redundant processing and inflated responses. This leads to uncontrolled resource consumption, resulting in denial of service.
References
Configurations
No configuration.
History
22 Jul 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in the Admin Console. An unauthenticated remote attacker can send specially crafted GET requests that trigger redundant processing and inflated responses. This leads to uncontrolled resource consumption, resulting in denial of service. |
10 Jul 2025, 13:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-09 17:15
Updated : 2025-07-22 16:15
NVD link : CVE-2025-53645
Mitre link : CVE-2025-53645
CVE.ORG link : CVE-2025-53645
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption