First published: Tue Aug 08 2017(Updated: )
Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information Disclosure Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =2012-sp3 | |
Microsoft SQL Server | =2014-sp1 | |
Microsoft SQL Server | =2014-sp2 | |
Microsoft SQL Server | =2016 | |
Microsoft SQL Server | =2016-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8516 has a severity rating of Important due to its potential for information disclosure.
To remediate CVE-2017-8516, apply the latest security updates provided by Microsoft for affected SQL Server versions.
CVE-2017-8516 affects Microsoft SQL Server 2012 SP3, 2014 SP1, 2014 SP2, and 2016.
CVE-2017-8516 is categorized as an information disclosure vulnerability.
CVE-2017-8516 is caused by improper enforcement of permissions in Microsoft SQL Server Analysis Services.