CVE-2017-8516 is an information disclosure vulnerability affecting Microsoft SQL Server Analysis Services in SQL Server 2012, 2014, and 2016 due to improper permission enforcement. It carries a CVSS v3.1 score of 7.5 (High), indicating a network-exploitable vulnerability with low attack complexity that could lead to significant data confidentiality impact. While no public exploit code or active exploitation is reported, the vulnerability has received some community discussion and media coverage, suggesting awareness within the security landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2012CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2012:sp3:*:*:*:*:*:* | ||
2014CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2014:sp1:*:*:*:*:*:* | ||
2014CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2014:sp2:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2016:*:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2016:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.