PT-2015-2327 · Microsoft · Sharepoint Server+1
Published
2015-10-13
·
Updated
2018-10-12
·
CVE-2015-2556
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Server versions 2007 SP3 through 2010 SP2
Description
The issue is related to the improper parsing of Document Type Definitions (DTDs) in XML files by the InfoPath Forms Services component, which can lead to an information disclosure vulnerability. This vulnerability can be exploited by a remote attacker to read arbitrary files on a SharePoint server by using a specially crafted XML document containing an external entity declaration. The attacker must have write permissions to a site and InfoPath Services must be enabled to exploit the vulnerability.
Recommendations
For Microsoft SharePoint Server 2007 SP3, update to a version that properly parses DTDs in XML files to prevent exploitation.
For Microsoft SharePoint Server 2010 SP2, update to a version that properly parses DTDs in XML files to prevent exploitation.
As a temporary workaround, consider disabling the InfoPath Forms Services component until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infopath Forms Services
Sharepoint Server