7.5
CVE-2017-8516
- EPSS 8.04%
- Veröffentlicht 08.08.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information Disclosure Vulnerability".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Sql Server Version 2012 Update sp3
Microsoft ≫ Sql Server Version 2014 Update sp1
Microsoft ≫ Sql Server Version 2014 Update sp2
Microsoft ≫ Sql Server Version 2016
Microsoft ≫ Sql Server Version 2016 Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.04% | 0.94 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.securityfocus.com/bid/100041
http://www.securitytracker.com/id/1039110
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8516