CVE-2023-36894: Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5408.1000Patch KB5002398 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.16130.20684Patch KB5002437 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10401.20025Patch KB5002422
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36894?
The severity of CVE-2023-36894 is high, with a severity value of 6.5.
Which versions of Microsoft SharePoint Server are affected by CVE-2023-36894?
Microsoft SharePoint Server 2016 and Microsoft SharePoint Server 2019 are affected by CVE-2023-36894.
How can I fix CVE-2023-36894?
Apply the appropriate patches or updates provided by Microsoft. For SharePoint Server 2016: [URL] For SharePoint Server 2019: [URL]
Where can I find more information about CVE-2023-36894?
You can find more information about CVE-2023-36894 on the Microsoft Security Response Center (MSRC) website: [URL]