CVE-2020-1439
Summary
| CVE | CVE-2020-1439 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-14 23:15:00 UTC |
| Updated | 2020-07-23 20:15:00 UTC |
| Description | A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Sharepoint Enterprise Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Foundation | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Foundation | 2013 | sp1 | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2019 | All | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2019 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-20-874 | Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1439 | MISC | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.