CERT-In Vulnerability Note
CIVN-2019-0201
Microsoft SharePoint Server Information Disclosure Vulnerability
Original Issue Date:December 24, 2019
Severity Rating: MEDIUM
Software Affected
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2010 SP2
- Microsoft SharePoint Foundation 2013 SP1
- Microsoft SharePoint Server 2019
Overview
A Vulnerability has been reported in Microsoft SharePoint which could allow a remote malicious user to obtain sensitive information from the targeted system.
Description
This vulnerability exists in Microsoft SharePoint. By sending a specially crafted request to a susceptible SharePoint Server instance, a remote attacker could exploit this vulnerability to read arbitrary files on the server.
Solution
Apply appropriate patches as mentioned in Microsoft security bulletin:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1491
Vendor Information
Microsoft
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1491
References
Microsoft
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1491
CVE Name
CVE-2019-1491
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|