Zimbra Collaboration Suite – SSRF Vulnerability

early warning alert
July 17, 2025
(CVE-2019-9621)
Early Warning
1480 Days Early

What is CVE-2019-9621?

CVE-2019-9621 is a server-side request forgery (SSRF) vulnerability found in several versions of the Zimbra Collaboration Suite (ZCS), an enterprise-class email, calendar, and collaboration platform. The vulnerability affects ZCS versions prior to 8.6 Patch 13, 8.7.x before 8.7.11 Patch 10, and 8.8.x before 8.8.10 Patch 7 or before 8.8.11 Patch 3. The issue resides within the ProxyServlet component, where insufficient privilege validation allows an attacker with a valid non-admin token to relay arbitrary network requests through the affected Zimbra server.

When was the vulnerability discovered?

The vulnerability was first discovered by security researcher An Trinh on March 19, 2019, and was published to NVD on April 30, 2019. Zimbra had already patched the issue by the time of disclosure. PoC exploits were released afterward, and a Metasploit module for the vulnerability is also available.

Armis Centrix™ for Early Warning added CVE-2019-9621 to the list of known vulnerabilities being exploited in the wild on June 18, 2021. By comparison, CISA placed CVE-2019-9621 into its Known Exploited Vulnerabilities catalog on July 7, 2025, making Armis Centrix™ for Early Warning 1480 days earlier.

CVE-2019-9621 threat alert chart

Significance of CVE-2019-9621:

Vulnerable component: The vulnerability is present in the ProxyServlet, introduced for proxying user-supplied requests without sufficient validation. External actors with valid non-admin tokens can convince the application to issue crafted HTTP requests to arbitrary hosts.

Exploitation scenario: By sending a malicious request to a vulnerable instance of Zimbra Collaboration Suite, an attacker can leverage the ProxyServlet to interact with internal systems, cloud metadata endpoints, or services protected behind firewalls. This behavior can be used for port scanning, information gathering, or serving as a stepping stone for further exploitation as shown by the original researcher who chained multiple vulnerabilities to obtain pre-auth RCE.

Impact and blast radius: Exploiting this SSRF flaw can expose internal resources or lead to remote code execution as shown by the researcher.

Value of Timely Awareness: Zimbra Collaboration Suite is frequently deployed and can be exposed to public subnets. Rapid awareness and action significantly reduce exposure to opportunistic and targeted attacks utilizing CVE-2019-9621. Immediate application of vendor-provided patches is crucial. Proactively monitoring system logs for suspicious requests further mitigates risk.

Mitigation and Protection:

Proactive defense and workarounds: Users of affected Zimbra Collaboration Suite versions must upgrade to 8.6 patch 13, 8.7.11 patch 10, 8.8.10 patch 7, 8.8.11 patch 3, or any later supported version

Continuous monitoring and updates: Security teams should routinely review Zimbra advisories and swiftly apply critical patches, conduct vulnerability scans on exposed systems, and monitor server logs for unexpected outbound requests or ProxyServlet activity.

Stay vigilant and ensure your systems are up-to-date to defend against evolving cybersecurity threats.

Armis Centrix™ for Early Warning is the proactive cybersecurity solution designed to empower organizations with early warning intelligence to anticipate and mitigate cyber risk effectively. Looking for real-time context, prioritization, and actionable insights tailored to your specific industry and threat levels? Make sure to check out our Armis Vulnerability Intelligence Database.

References: