We're getting hit with this one : CVE-2025-68645

Discuss your pilot or production implementation with other Zimbra admins or our engineers.
Post Reply
BradC
Outstanding Member
Outstanding Member
Posts: 428
Joined: Tue May 03, 2016 1:39 am

We're getting hit with this one : CVE-2025-68645

Post by BradC »

https://nvd.nist.gov/vuln/detail/CVE-2025-68645

It's exposing some internal server names and ip addresses, admin port numbers and a few other bits and pieces. Easy enough to run against your own server to see what it exposes :

https://yourservername/h/rest?javax.ser ... NF/web.xml
ghen
Outstanding Member
Outstanding Member
Posts: 413
Joined: Thu May 12, 2016 1:56 pm
Location: Belgium

Re: We're getting hit with this one : CVE-2025-68645

Post by ghen »

This has been fixed in Zimbra 10.0.18 and 10.1.13.
BradC
Outstanding Member
Outstanding Member
Posts: 428
Joined: Tue May 03, 2016 1:39 am

Re: We're getting hit with this one : CVE-2025-68645

Post by BradC »

Yes, I tried the "exploit" on an old backup that was still on 10.1.10

Still copping loads of attempts. Looks like not long after the CVE landed someone posted an example to twitter and the attempts started just after that.
ghen
Outstanding Member
Outstanding Member
Posts: 413
Joined: Thu May 12, 2016 1:56 pm
Location: Belgium

Re: We're getting hit with this one : CVE-2025-68645

Post by ghen »

I'm seeing just a handful of requests on /h/rest, all returning HTTP 500.
rainer_d
Advanced member
Advanced member
Posts: 146
Joined: Fri Sep 12, 2014 11:40 pm

Re: We're getting hit with this one : CVE-2025-68645

Post by rainer_d »

I can't upgrade at the moment.

Can I just block /h/rest globally on zimbra or is it needed for something?
zmcontrol
Advanced member
Advanced member
Posts: 70
Joined: Fri Jul 24, 2020 12:43 am

Re: We're getting hit with this one : CVE-2025-68645

Post by zmcontrol »

rainer_d wrote: Tue Jan 13, 2026 4:38 pm I can't upgrade at the moment.
rainer_d,

Here's a way to apply the fix without upgrading (the package url is for ubuntu 22).

viewtopic.php?p=317458#p317458
rainer_d
Advanced member
Advanced member
Posts: 146
Joined: Fri Sep 12, 2014 11:40 pm

Re: We're getting hit with this one : CVE-2025-68645

Post by rainer_d »

The problem is that I am on CentOS7.
I need to cross-grade to Rocky9 first. Then upgrade.

If I could just upgrade, I would.
ghen
Outstanding Member
Outstanding Member
Posts: 413
Joined: Thu May 12, 2016 1:56 pm
Location: Belgium

Re: We're getting hit with this one : CVE-2025-68645

Post by ghen »

The jar files are OS independent.
Post Reply