Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.815501
Category:Windows : Microsoft Bulletins
Title:Microsoft SharePoint Enterprise Server 2016 Multiple Vulnerabilities (KB4475520)
Summary:This host is missing an important security; update according to Microsoft KB4475520
Description:Summary:
This host is missing an important security
update according to Microsoft KB4475520

Vulnerability Insight:
Multiple flaws exist due to:

- An authentication bypass vulnerability exists in Windows Communication
Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing
of SAML tokens with arbitrary symmetric keys.

- A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint
Server does not properly sanitize a specially crafted web request to an affected
SharePoint server.

Vulnerability Impact:
Successful exploitation will allow an attacker
to perform cross-site scripting attacks on affected systems and run script in
the security context of the current user and read content that the attacker is
not authorized to read, use the victim's identity to take actions on the
SharePoint site on behalf of the user.

Affected Software/OS:
Microsoft SharePoint Enterprise Server 2016.

Solution:
The vendor has released updates. Please see
the references for more information.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-1134
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1134
Common Vulnerability Exposure (CVE) ID: CVE-2019-1006
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1006
CopyrightCopyright (C) 2019 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.