PT-2022-17932 · Zarafa+3 · Zarafa Collaboration Platform+3

Published

2022-04-01

·

Updated

2024-07-04

·

CVE-2022-26562

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kopano Core versions 11.0.2.51 and earlier Zarafa Collaboration Platform versions 6.30 through 6.30.8
Description The issue allows attackers to authenticate even if the user account or password is expired. This is due to a problem in the provider/libserver/ECKrbAuth.cpp file of Kopano Core and the provider/libserver/ECPamAuth.cpp file of Zarafa Collaboration Platform.
Recommendations For Kopano Core versions 11.0.2.51 and earlier, update to a version later than 11.0.2.51 to resolve the issue. For Zarafa Collaboration Platform versions 6.30 through 6.30.8, consider disabling the authentication mechanism in ECPamAuth.cpp until a patch is available. As a temporary workaround, restrict access to the affected authentication module to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-26562
DLA-3354-1
USN-6876-1

Affected Products

Kopano Core
Linuxmint
Ubuntu
Zarafa Collaboration Platform