CVE-2018-0789
Summary
| CVE | CVE-2018-0789 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-10 01:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0790. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Sharepoint Enterprise Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft SharePoint Server CVE-2018-0789 Remote Privilege Escalation Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0789 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| Microsoft SharePoint Input Validation Flaws Let Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.