Exposição de Microsoft SharePoint

CMS
15
score de exposição
2.158
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades do Microsoft SharePoint no catálogo soma 52 CVEs, nenhuma das quais está atualmente confirmada em exploração ativa pelo CISA KEV, resultado abaixo da média geral do catálogo. Não há registros de severidade crítica nem de novas vulnerabilidades surgidas nos últimos 90 dias, o que indica um período recente de relativa estabilidade para a plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora comum em aplicações web, exige atenção continuada em ambientes corporativos onde o SharePoint processa conteúdo de múltiplos usuários. A CVE com maior pontuação EPSS no conjunto é CVE-2019-0585, com valor de aproximadamente 0,22, sugerindo probabilidade moderada de tentativa de exploração — organizações que ainda mantêm versões antigas do produto devem verificar se essa vulnerabilidade foi devidamente remediada.

CVEs

52 resultados
CVE-2018-0915Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how sEPSS 4.5%CVE-2018-0916Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how sEPSS 4.5%CVE-2018-8580An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cEPSS 4.4%CVE-2017-11936Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "MicEPSS 4.2%CVE-2017-8551An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aEPSS 3.3%CVE-2017-8514An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aEPSS 3.0%CVE-2018-8149An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.9%CVE-2018-8155An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.9%CVE-2018-8156An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.9%CVE-2018-8518An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.8%CVE-2018-8252An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.8%CVE-2018-8254An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.8%CVE-2018-8323An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.5%CVE-2018-8299An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.5%CVE-2018-8168An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.4%CVE-2018-8568MEDIUMAn elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.3%CVE-2018-8488An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.3%CVE-2018-8498An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.3%CVE-2018-8480An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.3%CVE-2018-8426A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 2.3%