5.5
CVE-2012-1860
- EPSS 1.45%
- Published 10.07.2012 21:55:05
- Last modified 11.04.2025 00:51:21
- Source secure@microsoft.com
- Teams watchlist Login
- Open Login
Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
Data is provided by the National Vulnerability Database (NVD)
Microsoft ≫ Office Web Apps Version2010
Microsoft ≫ Office Web Apps Version2010 Updatesp1
Microsoft ≫ Sharepoint Server Version2007 Updatesp1
Microsoft ≫ Sharepoint Server Version2007 Updatesp2
Microsoft ≫ Sharepoint Server Version2007 Updatesp3
Microsoft ≫ Sharepoint Server Version2010
Microsoft ≫ Sharepoint Server Version2010 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.45% | 0.789 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:P
|