cbcvebase.
CVE-2019-1202
published 2019-08-14

CVE-2019-1202: An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited…

medium4.4CVSS 3.0
AVLACLPRLUINSUCLILAN
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker could run a specially crafted application. The security update corrects how SharePoint handles session objects to prevent user session hijacking.

Affected

12 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_foundation_2010_service_pack_2>= 13.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_foundation_2013_service_pack_1>= 15.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < publicationpublication
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_foundation
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2010_service_pack_2
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2019