Vulnerability Description
SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Sharepoint Server | 2013 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102962Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040376Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0864PatchVendor Advisory
- http://www.securityfocus.com/bid/102962Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040376Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0864PatchVendor Advisory
FAQ
What is CVE-2018-0864?
CVE-2018-0864 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure...
How severe is CVE-2018-0864?
CVE-2018-0864 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0864?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Sharepoint Server.