cbcvebase.
CVE-2020-16942
published 2020-10-16

CVE-2020-16942: An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An…

medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page. To take advantage of the vulnerability, an attacker would require access to the specific SharePoint page affected by this vulnerability. The security update addresses the vulnerability by correcting how scripts are referenced on some SharePoint pages.

Affected

13 ranges
VendorProductVersion rangeFixed in
fasterxmljackson-databind>= 0 < 2.4.2-3ubuntu0.1~esm22.4.2-3ubuntu0.1~esm2
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_foundation_2010_service_pack_2>= 13.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_foundation_2013_service_pack_1>= 15.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < publicationpublication
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_foundation
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2010_service_pack_2
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2019

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL