Exposición de Microsoft SharePoint

CMS
15
score de exposición
2158
sitios usan
0
en explotación
0
críticos
Análisis Vexday

O histórico de vulnerabilidades do Microsoft SharePoint no catálogo soma 52 CVEs, nenhuma das quais está atualmente confirmada em exploração ativa pelo CISA KEV, resultado abaixo da média geral do catálogo. Não há registros de severidade crítica nem de novas vulnerabilidades surgidas nos últimos 90 dias, o que indica um período recente de relativa estabilidade para a plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora comum em aplicações web, exige atenção continuada em ambientes corporativos onde o SharePoint processa conteúdo de múltiplos usuários. A CVE com maior pontuação EPSS no conjunto é CVE-2019-0585, com valor de aproximadamente 0,22, sugerindo probabilidade moderada de tentativa de exploração — organizações que ainda mantêm versões antigas do produto devem verificar se essa vulnerabilidade foi devidamente remediada.

CVEs

52 resultados
CVE-2018-0915Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how sEPSS 4.1%CVE-2018-0916Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how sEPSS 4.1%CVE-2018-0921Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanEPSS 4.1%CVE-2018-0923Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanEPSS 4.1%CVE-2018-0944Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how EPSS 4.1%CVE-2018-0947Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to duEPSS 4.1%CVE-2018-8156An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 4.0%CVE-2018-8149An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 4.0%CVE-2018-8155An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 4.0%CVE-2017-11936Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "MicEPSS 4.0%CVE-2018-8252An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.8%CVE-2018-8254An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.8%CVE-2018-8323An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.5%CVE-2018-8299An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.5%CVE-2018-8168An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.5%CVE-2018-8498An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.2%CVE-2018-8480An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.2%CVE-2018-8488An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.2%CVE-2018-8431An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 3.2%CVE-2018-8426A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 3.2%