Vulnerability Description
Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0923 and CVE-2018-0944.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Sharepoint Enterprise Server | 2013 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103306Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040513Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0947PatchVendor Advisory
- http://www.securityfocus.com/bid/103306Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040513Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0947PatchVendor Advisory
FAQ
What is CVE-2018-0947?
CVE-2018-0947 is a vulnerability with a CVSS score of 8.8 (HIGH). Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Mic...
How severe is CVE-2018-0947?
CVE-2018-0947 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0947?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Sharepoint Enterprise Server.