{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2019-9621",
  "revision": 1,
  "title": "Zimbra Collaboration — request forgery in the proxy servlet",
  "summary": "Zimbra Collaboration before the 8.6, 8.7 and 8.8 patch releases lets an attacker make the server issue requests of their choosing through its proxy component, reaching systems only the server can see.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.5,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "version": "3.1"
  },
  "epss": 0.81037,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2025-07-07",
    "prerequisites": "Network access to the Zimbra web front end; no credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade Zimbra past 8.6p13, 8.7.11p10, 8.8.10p7 or 8.8.11p3 now; exploit code is public, so review outbound requests made by the server.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2019-9621",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2019-9621",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2019-9621",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9621",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://blog.zimbra.com/2019/03/9826/"
    },
    {
      "type": "vendor_advisory",
      "url": "https://wiki.zimbra.com/wiki/Security_Center"
    },
    {
      "type": "vendor_advisory",
      "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories"
    }
  ],
  "published_at": "2019-04-30T18:29:08.633Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "zimbra",
    "webmail",
    "ssrf",
    "kev"
  ]
}
