← All CVEs

CVE-2020-1439

high · 8.8

A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.

8.8
CVSS
20.3%
EPSS (exploit prob.)
97th
EPSS percentile
2020-07-14
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
microsoftsharepoint_enterprise_server2013
microsoftsharepoint_enterprise_server2016
microsoftsharepoint_foundation2013
microsoftsharepoint_server2010
microsoftsharepoint_server2019

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-1439