CVE-2020-1439 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.

EPSS 31.15% · 96.7th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
31.15%
96.7th percentile

Affected Products

VendorProductVersions
microsoftsharepoint_server2019, 2010
MicrosoftMicrosoft SharePoint Enterprise Server2013 Service Pack 1, 2016
microsoftsharepoint_foundation2013
MicrosoftMicrosoft SharePoint Server2010 Service Pack 2, 2019
MicrosoftMicrosoft SharePoint Foundation2013 Service Pack 1
microsoftsharepoint_enterprise_server2013, 2016

Timeline

References

Open in Interactive Console →