{"id":"CVE-2018-10949","details":"mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the \"HTTP 404 - account is not active\" and \"HTTP 401 - must authenticate\" errors.","modified":"2026-07-08T05:52:08.451128951Z","published":"2018-05-10T01:29:05.657Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:synacor:zimbra_collaboration_suite:8.6.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.6.0"},{"last_affected":"8.6.0"},{"introduced":"8.6.0"},{"last_affected":"8.6.0"},{"introduced":"8.6.0"},{"last_affected":"8.6.0"},{"introduced":"8.6.0"},{"last_affected":"8.6.0"}],"source":"CPE_STRING","vendor_product":"synacor:zimbra_collaboration_suite"}]},"references":[{"type":"REPORT","url":"https://bugzilla.zimbra.com/show_bug.cgi?id=108962"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-build","events":[{"introduced":"0"},{"last_affected":"6c3c77b328a0d7d3bafecb79d202960217922ef0"},{"fixed":"a12f6b5f02776dff1d0554a7998ae6c6ee0dd820"}],"database_specific":{"cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.7.0"},{"last_affected":"8.7.11"},{"introduced":"8.8"},{"fixed":"8.8.8"}],"source":"CPE_RANGE"}}],"versions":["8.7.11","8.8.7","8.8.6","8.8.4","8.8.3","8.8.2","8.8.0.beta1","8.7.10","8.7.9","8.7.7","8.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10949.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-mailbox","events":[{"introduced":"0"},{"last_affected":"65929222951131db2cbb2378accbdd5f2fac0980"},{"fixed":"49778e9798e139cb059be07aa1810a2d624ef888"}],"database_specific":{"extracted_events":[{"introduced":"8.7.0"},{"last_affected":"8.7.11"},{"introduced":"8.8"},{"fixed":"8.8.8"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*"}}],"versions":["8.7.6","8.7.11","8.8.7","8.8.6","8.8.5","8.8.4","8.8.3","8.8.2","8.7.10","8.7.9","8.7.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10949.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs","events":[{"introduced":"0"},{"last_affected":"e177bad87d5312e7b2cd1915ae8c0cd2528cacdb"},{"fixed":"34aff8ccf0b1b56d129015c54153bf823915f8ce"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.7.0"},{"last_affected":"8.7.11"},{"introduced":"8.8"},{"fixed":"8.8.8"}]}}],"versions":["8.7.11","8.8.7","8.8.6","8.8.5","8.8.4","8.8.3","8.8.2","8.8.0beta2","8.8.0.beta1","8.7.10","8.7.9","8.7.7","8.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10949.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs-lib","events":[{"introduced":"0"},{"last_affected":"a1cbf80618e47b3cf0894cbbcaec1da9bece583c"},{"fixed":"048ff3fb24f199ee7081e4f1504ec965cdc98be6"}],"database_specific":{"cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.7.0"},{"last_affected":"8.7.11"},{"introduced":"8.8"},{"fixed":"8.8.8"}],"source":"CPE_RANGE"}}],"versions":["8.7.11","8.8.7","8.8.6","8.8.5","8.8.4","8.8.3","8.8.2","8.8.0.beta1","8.7.10","8.7.9","8.7.7","8.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10949.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}