Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of Service Vulnerability."
| Software | From | Fixed in |
|---|---|---|
| microsoft / sharepoint_services | 3.0 | 3.0.x |
| microsoft / sharepoint_foundation | 2010-sp2 | 2010-sp2.x |
| microsoft / sharepoint_server | 2007-sp3 | 2007-sp3.x |
| microsoft / sharepoint_foundation | 2013 | 2013.x |
| microsoft / sharepoint_server | 2013 | 2013.x |
| microsoft / sharepoint_server | 2010-sp2 | 2010-sp2.x |
| microsoft / sharepoint_services | 2.0 | 2.0.x |
| microsoft / sharepoint_server | 2010-sp1 | 2010-sp1.x |
| microsoft / sharepoint_portal_server | 2003-sp3 | 2003-sp3.x |
| microsoft / sharepoint_foundation | 2010-sp1 | 2010-sp1.x |