Impact
A relative path traversal flaw exists in Microsoft SharePoint Server that permits an attacker with authorized credentials to read files and directories outside those intended for access. The vulnerability enables the disclosure of internal data over the network, potentially exposing sensitive information and compromising confidentiality. It is classified as a medium severity problem, as reflected by the CVSS score of 6.5.
Affected Systems
The flaw affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific sub‑version ranges are listed, so all releases within these product families are potentially impacted.
Risk and Exploitability
The EPSS score indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker already be authenticated to the SharePoint environment, implying that it hinges on privilege escalation or compromised credentials. Given the moderate severity and the low exploitation probability, the risk is considered moderate but still warrants careful review of access controls and timely application of vendor fixes.
OpenCVE Enrichment