Product: Zimbra Collaboration Suite Vendor: VMWare Vulnerable Version: 6.0.16 and probably prior Tested Version: 6.0.16 Vendor Notification: 09/03/2013 Public Disclosure: 09/13/2013 Vulnerability Type: Authentication Bypass by Capture-replay (CWE-294) CVE: CVE-2013-5119 Discovered and Provided By: Brian Warehime (Aplura LLC) ---------------------------------------------------------------------- Advisory Details: A vulnerability exists in Zimbra Collaboration Suite (ZCS) which can be exploited to bypass authentication by replaying a captured session token. A remote attacker can sniff network traffic and obtain an authorized user's session token and modify the token on the attacker's machine to replay the token and successfully log in. If an attacker can capture the ZM_AUTH_TOKEN after a user has successfully logged in, the attacker can then create a new ZM_AUTH_TOKEN with the same information and log in, even after the other user logs out. -------------------------------------------------------------------------------------------------- Solution: Upgrade to the latest version of ZCS.