Lucene search

K
cve[email protected]CVE-2018-8578
HistoryNov 14, 2018 - 1:29 a.m.

CVE-2018-8578

2018-11-1401:29:01
web.nvd.nist.gov
43
cve-2018-8578
information disclosure
microsoft
sharepoint
vulnerability
nvd

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

5.3 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.7%

An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka “Microsoft SharePoint Information Disclosure Vulnerability.” This affects Microsoft SharePoint.

Affected configurations

Vulners
NVD
Node
microsoftsharepoint_services
VendorProductVersionCPE
microsoftsharepoint_services*cpe:2.3:a:microsoft:sharepoint_services:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Microsoft SharePoint",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Enterprise Server 2013 Service Pack 1"
      }
    ]
  }
]

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

5.3 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.7%