CVE-2018-0864

MEDIUM

SharePoint Server - Information Disclosure via Web Request Handling

Title source: llm
STIX 2.1

Description

SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102962
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040376

Scores

CVSS v3 5.4
EPSS 0.0241
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
microsoft/sharepoint_server 2013 sp1
microsoft/sharepoint_server 2016
Published Feb 15, 2018
Tracked Since Feb 18, 2026