<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker would need to be authenticated on an affected SharePoint Server. The attacker would then need to send a specially modified request to the server, targeting a specific user.</p> <p>The security update addresses the vulnerability by modifying how Microsoft SharePoint Server handles profile data.</p>
2020-09-11T17:15:20.683
2024-11-21T05:10:33.393
Modified
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | sharepoint_enterprise_server | 2013 | Yes |
Application | microsoft | sharepoint_enterprise_server | 2016 | Yes |
Application | microsoft | sharepoint_server | 2010 | Yes |
Application | microsoft | sharepoint_server | 2019 | Yes |