6.6
CVSSv2

CVE-2015-3436

Published: 09/06/2015 Updated: 06/12/2016
CVSS v2 Base Score: 6.6 | Impact Score: 9.2 | Exploitability Score: 3.9
VMScore: 587
Vector: AV:L/AC:L/Au:N/C:N/I:C/A:C

Vulnerability Summary

provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) prior to 7.1.13 and 7.2.x prior to 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zarafa zarafa collaboration platform 7.2.0

zarafa zarafa collaboration platform