CVE-2019-1068
https://notcve.org/view.php?id=CVE-2019-1068
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. Se presenta una vulnerabilidad de ejecución de código remota en Microsoft SQL Server cuando se maneja incorrectamente el procesamiento de funciones internas, también se conoce como 'Microsoft SQL Server Remote Code Execution Vulnerability'. • https://github.com/Vulnerability-Playground/CVE-2019-1068 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 •
CVE-2019-0819
https://notcve.org/view.php?id=CVE-2019-0819
An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata permissions, aka 'Microsoft SQL Server Analysis Services Information Disclosure Vulnerability'. Se presenta una vulnerabilidad de divulgación de información en Microsoft SQL Server Analysis Services cuando aplica inapropiadamente permisos metadata, también se conoce como 'Microsoft SQL Server Analysis Services Information Disclosure Vulnerability'. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0819 •
CVE-2018-8532 – Microsoft SQL Server Management Studio xmla File XML External Entity Processing Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2018-8532
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8533. Existe una vulnerabilidad de divulgación de información en Microsoft SQL Server Management Studio (SSMS) al analizar un archivo XMLA malicioso que contiene una referencia a una entidad externa. Esto también se conoce como "SQL Server Management Studio Information Disclosure Vulnerability". • https://www.exploit-db.com/exploits/45587 http://www.securityfocus.com/bid/105475 http://www.securitytracker.com/id/1041826 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8532 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2018-8533 – Microsoft SQL Server Management Studio regsrvr File XML External Entity Processing Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2018-8533
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8532. Existe una vulnerabilidad de divulgación de información en Microsoft SQL Server Management Studio (SSMS) al analizar contenido XML malicioso que contiene una referencia a una entidad externa. Esto también se conoce como "SQL Server Management Studio Information Disclosure Vulnerability". • https://www.exploit-db.com/exploits/45583 http://www.securityfocus.com/bid/105476 http://www.securitytracker.com/id/1041826 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8533 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2018-8527 – Microsoft SQL Server Management Studio xel File XML External Entity Processing Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2018-8527
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8532, CVE-2018-8533. Existe una vulnerabilidad de divulgación de información en Microsoft SQL Server Management Studio (SSMS) al analizar un archivo XEL malicioso que contiene una referencia a una entidad externa. Esto también se conoce como "SQL Server Management Studio Information Disclosure Vulnerability". • https://www.exploit-db.com/exploits/45585 http://www.securityfocus.com/bid/105474 http://www.securitytracker.com/id/1041826 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8527 • CWE-611: Improper Restriction of XML External Entity Reference •