VulnerabilityModified
CVE-2018-0864
SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
MEDIUM 5.4EPSS 2.57%
Does this matter?
Lower severity and a low EPSS score (2.57%). Track it; it rarely justifies an emergency change on its own.
Description
SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.57% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/sharepoint server
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/102962Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040376Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0864Patch, Vendor Advisory
- http://www.securityfocus.com/bid/102962Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040376Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0864Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.