Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
CISA entryMicrosoft · AUTOMATIC DISCOVERY
Microsoft SharePoint is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
Microsoft SharePoint is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Used to provide application, infrastructure or operational services to other systems and users.
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
| Product | Microsoft SharePoint |
|---|---|
| Release | Microsoft SharePoint Server 2010 |
| End of Support | 13 April 2021 |
| Date precision | Day |
These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
CISA entryMicrosoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
CISA entryMicrosoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
CISA entryMicrosoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CISA entryMicrosoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
CISA entryMicrosoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CISA entryShowing the 6 most recently added of 16 product-family matches.
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
summary | start | end | title | last_modified | locale | products | display_products | url | Microsoft SharePoint Server 2010 follows the Fixed Lifecycle Policy. | 2010-07-15T08:00:00Z | 2021-04-14T06:59:59.999Z | Microsoft SharePoint Server 2010 | 2022-10-25T00:00:00Z | en-us | ['office'] | ['Office'] | /lifecycle/products/microsoft-sharepoint-server-2010
Official vendor lifecycle or product-change property. Extracted records require human review.
Open official vendor source