PT-2015-2335 · Microsoft · Office Web Apps Server+5

Publicado

2015-10-13

·

Atualizado

2018-10-12

·

CVE-2015-6037

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Excel Services on SharePoint Server versions 2010 SP2 through 2013 SP1 Office Web Apps versions 2010 SP2 through 2013 SP1 Excel Web App version 2010 SP2 Office Web Apps Server version 2013 SP1 SharePoint Foundation version 2013 SP1
Description The issue allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. An attacker could exploit this by sending a specially crafted request to an affected Office Web Apps Server, potentially leading to cross-site scripting attacks. These attacks could allow the attacker to read unauthorized content, use the victim's identity to take actions on the Office Web App site, change permissions, delete content, steal sensitive information, and inject malicious content in the victim's browser. For this issue to be exploited, a user must click a specially crafted URL that takes the user to a targeted Office Web App site.
Recommendations For Microsoft Excel Services on SharePoint Server 2010 SP2, update to a version that includes the fix for this issue. For Microsoft Excel Services on SharePoint Server 2013 SP1, update to a version that includes the fix for this issue. For Office Web Apps 2010 SP2, update to a version that includes the fix for this issue. For Office Web Apps 2013 SP1, update to a version that includes the fix for this issue. For Excel Web App 2010 SP2, update to a version that includes the fix for this issue. For Office Web Apps Server 2013 SP1, update to a version that includes the fix for this issue. For SharePoint Foundation 2013 SP1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the vulnerable Office Web Apps Server to minimize the risk of exploitation. Avoid using specially crafted URLs in the affected Office Web App sites until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11700
CVE-2015-6037

Produtos afetados

Excel Web App
Excel Services
Office Web Apps
Office Web Apps Server
Sharepoint Foundation
Sharepoint Server