Lucene search

K
nvd[email protected]NVD:CVE-2012-1860
HistoryJul 10, 2012 - 9:55 p.m.

CVE-2012-1860

2012-07-1021:55:05
CWE-264
web.nvd.nist.gov
7

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

55.2%

Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka “SharePoint Search Scope Vulnerability.”

Affected configurations

Nvd
Node
microsoftoffice_web_appsMatch2010
OR
microsoftoffice_web_appsMatch2010sp1
OR
microsoftsharepoint_serverMatch2007sp1
OR
microsoftsharepoint_serverMatch2007sp2
OR
microsoftsharepoint_serverMatch2007sp3
OR
microsoftsharepoint_serverMatch2010
OR
microsoftsharepoint_serverMatch2010sp1
VendorProductVersionCPE
microsoftoffice_web_apps2010cpe:2.3:a:microsoft:office_web_apps:2010:*:*:*:*:*:*:*
microsoftoffice_web_apps2010cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*
microsoftsharepoint_server2007cpe:2.3:a:microsoft:sharepoint_server:2007:sp1:*:*:*:*:*:*
microsoftsharepoint_server2007cpe:2.3:a:microsoft:sharepoint_server:2007:sp2:*:*:*:*:*:*
microsoftsharepoint_server2007cpe:2.3:a:microsoft:sharepoint_server:2007:sp3:*:*:*:*:*:*
microsoftsharepoint_server2010cpe:2.3:a:microsoft:sharepoint_server:2010:*:*:*:*:*:*:*
microsoftsharepoint_server2010cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

55.2%