CVE-2021-34519MediumCVSS 5.3

Microsoft SharePoint Server Information Disclosure Vulnerability

Published
July 13, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software? Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is Personally Identifiable Information (PII).

🎯 Affected products3

  • Microsoft SharePoint Enterprise Server 2013 Service Pack 1
  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Foundation 2013 Service Pack 1

✅ Remediation

KB5001976 (Security Update) — fixed build 16.0.5188.1000 KB5001981 (Security Update) — fixed build 16.0.5188.1000 KB5001984 (Security Update) — fixed build 15.0.5363.1000 KB5001992 (Security Update) — fixed build 15.0.5363.1000 KB5001996 (Security Update) — fixed build 15.0.5363.1000

🔗 References (13)