AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-2556

MEDIUM · CVSS 4.3 EPSS 15.62%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-10-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2015-2556
Severity
MEDIUM
CVSS
4.3
EPSS
15.62%
Microsoft SharePoint

Original NVD Description

The InfoPath Forms Services component in Microsoft SharePoint Server 2007 SP3 and 2010 SP2 misparses DTDs, which allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "Microsoft SharePoint Information Disclosure Vulnerability."