PT-2015-2327 · Microsoft · Sharepoint Server+1

Published

2015-10-13

·

Updated

2018-10-12

·

CVE-2015-2556

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server versions 2007 SP3 through 2010 SP2
Description The issue is related to the improper parsing of Document Type Definitions (DTDs) in XML files by the InfoPath Forms Services component, which can lead to an information disclosure vulnerability. This vulnerability can be exploited by a remote attacker to read arbitrary files on a SharePoint server by using a specially crafted XML document containing an external entity declaration. The attacker must have write permissions to a site and InfoPath Services must be enabled to exploit the vulnerability.
Recommendations For Microsoft SharePoint Server 2007 SP3, update to a version that properly parses DTDs in XML files to prevent exploitation. For Microsoft SharePoint Server 2010 SP2, update to a version that properly parses DTDs in XML files to prevent exploitation. As a temporary workaround, consider disabling the InfoPath Forms Services component until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11692
CVE-2015-2556

Affected Products

Infopath Forms Services
Sharepoint Server