Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-21968

Опубликовано: 08 фев. 2022
Источник: msrc
CVSS3: 4.3
EPSS Низкий

Описание

Microsoft SharePoint Server Security Feature Bypass Vulnerability

FAQ

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?

The attacker must have read access to the target site within SharePoint.

What kind of security feature could be bypassed by successfully exploiting this vulnerability?

The attacker would be able to bypass the protection in SharePoint blocking the HTTP request based on IP range. If an attacker successfully exploited this vulnerability, they could validate the presence or absence of an HTTP endpoint within the blocked IP range.

Обновления

ПродуктСтатьяОбновление
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server 2019
Microsoft SharePoint Server Subscription Edition

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 77%
0.01016
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
почти 4 года назад

Microsoft SharePoint Server Security Feature Bypass Vulnerability

CVSS3: 4.3
github
почти 4 года назад

Microsoft SharePoint Server Security Feature BypassVulnerability.

CVSS3: 4.3
fstec
почти 4 года назад

Уязвимость пакетов программ Microsoft SharePoint Server, Microsoft SharePoint Server Subscription Edition, программного обеспечения для электронного документооборота Microsoft SharePoint Foundation, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 77%
0.01016
Низкий

4.3 Medium

CVSS3