Impact
Microsoft Office SharePoint includes a server‑side request forgery flaw that permits an authorized attacker to instruct the server to make arbitrary outbound requests, thereby exposing internal network information. The vulnerability enables the disclosure of sensitive data over a network, potentially revealing configuration details, internal resource addresses, or other confidential information. It is categorized as CWE‑918, indicating a lack of proper request validation on the server side.
Affected Systems
The vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. All configured instances of these products are potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity. The EPSS score of less than 1% indicates a low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. It is exploitable by an attacker with legitimate authorized access, by leveraging the SSRF code path to trigger outbound connections to internal resources.
OpenCVE Enrichment