CVE-2019-1313
MEDIUMMicrosoft SQL Server Management Studio - Info Disclosure
Title source: llmDescription
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1313
Scores
CVSS v3
6.5
EPSS
0.0496
EPSS Percentile
91.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-755
Status
published
Products (2)
microsoft/sql_server_management_studio
18.3
microsoft/sql_server_management_studio
18.3.1
Published
Oct 10, 2019
Tracked Since
Feb 18, 2026