Release date:
Updated on:
Affected Systems:
Microsoft SharePoint Server 2010
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54314
Cve id: CVE-2012-1860
SharePoint Server is a Server function integration suite that provides comprehensive Content Management and Enterprise Search, accelerating shared business processes and simplifying cross-border information sharing.
The information leakage vulnerability exists when SharePoint stores the search range, allowing attackers to view or intervene in the search range of other users.
<* Source: Microsoft
Link: http://secunia.com/advisories/49875/
Http://www.microsoft.com/technet/security/bulletin/MS12-050.asp
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS12-050) and patches for this:
MS12-050: Vulnerabilities in SharePoint cocould Allow Elevation of Privilege (2695502)
Link: http://www.microsoft.com/technet/security/bulletin/MS12-050.asp