cbcvebase.
CVE-2017-8516
published 2017-08-08

CVE-2017-8516: Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information Disclosure Vulnerability".

Affected

12 ranges
VendorProductVersion rangeFixed in
microsoftsql_server
microsoftsql_server
microsoftsql_server
microsoft_corporationsql_server
msrcmicrosoft_sql_server_2012_for_32-bit_systems_service_pack_3
msrcmicrosoft_sql_server_2012_for_x64-based_systems_service_pack_3
msrcmicrosoft_sql_server_2014_service_pack_1_for_32-bit_systems
msrcmicrosoft_sql_server_2014_service_pack_1_for_x64-based_systems
msrcmicrosoft_sql_server_2014_service_pack_2_for_32-bit_systems
msrcmicrosoft_sql_server_2014_service_pack_2_for_x64-based_systems
msrcmicrosoft_sql_server_2016_for_x64-based_systems
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_1