PT-2013-2085 · Microsoft · Sharepoint Server 2013+5
Published
2013-09-11
·
Updated
2018-10-12
·
CVE-2013-0081
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Portal Server 2003 SP3
Microsoft SharePoint Server 2007 SP3
Microsoft SharePoint Server 2010 SP1
Microsoft SharePoint Server 2010 SP2
Microsoft SharePoint Server 2013
Description
A denial of service issue exists due to improper processing of unassigned workflows, allowing remote attackers to cause a denial of service via a crafted URL. This can lead to the W3WP process hanging, making the SharePoint site and other sites under the same process unavailable until the process is restarted.
Recommendations
For Microsoft SharePoint Portal Server 2003 SP3, update to a version that properly processes unassigned workflows.
For Microsoft SharePoint Server 2007 SP3, update to a version that properly processes unassigned workflows.
For Microsoft SharePoint Server 2010 SP1, update to a version that properly processes unassigned workflows.
For Microsoft SharePoint Server 2010 SP2, update to a version that properly processes unassigned workflows.
For Microsoft SharePoint Server 2013, update to a version that properly processes unassigned workflows.
As a temporary workaround, consider restricting access to crafted URLs that could exploit the denial of service vulnerability until a patch is available.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharepoint Portal Server 2003
Sharepoint Server 2007
Sharepoint Server 2010
Sharepoint Server 2013
Sharepoint Foundation
Sharepoint Server