First published: Wed Aug 14 2019(Updated: )
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server | =2016 | |
Microsoft SharePoint Foundation | =2010-sp2 | |
Microsoft SharePoint Foundation | =2013-sp1 | |
Microsoft SharePoint Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1202 has a severity rating of important, indicating a moderate risk to affected systems.
To fix CVE-2019-1202, apply the latest security updates provided by Microsoft for the affected SharePoint versions.
CVE-2019-1202 affects Microsoft SharePoint Foundation 2010 SP2, 2013 SP1, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
CVE-2019-1202 can lead to information disclosure, allowing attackers to gain access to sensitive session information.
There are currently no recommended workarounds for CVE-2019-1202, so applying the security update is advised.