CVE-2017-8516
Summary
| CVE | CVE-2017-8516 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-08 21:29:00 UTC |
| Updated | 2022-10-27 01:04:00 UTC |
| Description | Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information Disclosure Vulnerability". |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Sql Server | 2012 | sp3 | All | All |
| Application | Microsoft | Sql Server | 2014 | sp1 | All | All |
| Application | Microsoft | Sql Server | 2014 | sp2 | All | All |
| Application | Microsoft | Sql Server | 2016 | All | All | All |
| Application | Microsoft | Sql Server | 2016 | sp1 | All | All |
| Application | Microsoft | Sql Server | 2012 | sp3 | All | All |
| Application | Microsoft | Sql Server | 2014 | sp1 | All | All |
| Application | Microsoft | Sql Server | 2014 | sp2 | All | All |
| Application | Microsoft | Sql Server | 2016 | All | All | All |
| Application | Microsoft | Sql Server | 2016 | sp1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft SQL Server Analysis Services Permissions Flaw Lets Remote Authenticated Users Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Microsoft SQL Server CVE-2017-8516 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| {{windowTitle}} | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.