VulnerabilityModified
CVE-2018-8578
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft…
MEDIUM 4.3EPSS 4.88%
Does this matter?
Lower severity and a low EPSS score (4.88%). Track it; it rarely justifies an emergency change on its own.
Description
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 4.88% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/sharepoint enterprise server
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/105832Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042133Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8578Patch, Vendor Advisory
- http://www.securityfocus.com/bid/105832Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042133Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8578Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.