Description
An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced between 6.30.0 RC1e and 6.30.8 final).
Published: 2022-04-01
Score: 9.8 Critical
EPSS: 2.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3354-1 kopanocore security update
EUVD EUVD EUVD-2022-31118 An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced between 6.30.0 RC1e and 6.30.8 final).
Ubuntu USN Ubuntu USN USN-6876-1 Kopano Core vulnerabilities
History

No history.

Subscriptions

Kopano Groupware Core
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T05:03:32.956Z

Reserved: 2022-03-07T00:00:00.000Z

Link: CVE-2022-26562

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-01T20:15:08.227

Modified: 2024-11-21T06:54:08.530

Link: CVE-2022-26562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses