Researchers disclosed a post-authentication server-side request forgery (SSRF) flaw in Microsoft SharePoint Server 2019 affecting the /<site>/_api/web/ExecuteRemoteLOB endpoint. The vulnerability lets an authenticated user with access to a valid SharePoint site send highly customizable HTTP(S) requests to arbitrary URLs and read response bodies when the target returns a 2xx status, creating opportunities for internal network scanning and interaction with internal services.
The issue was traced to Microsoft.SharePoint.BusinessData.SystemSpecific.OData.ODataHybridHelper.InvokeODataService in Microsoft.SharePoint.dll, which builds an HttpWebRequest from attacker-controlled BCSOData-* headers and can also forward request bodies for POST and PUT methods. STAR Labs said it reproduced the bug on Windows Server 2022 running SharePoint Server 2019 version 16.0.10386.20011 with KB5002207, and identified affected versions as SharePoint Server 2019 up to 16.0.10386.20011; Microsoft later fixed the flaw, but no CVE identifier was assigned.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
STAR Labs published technical details and a proof of concept for the post-authentication SSRF vulnerability in Microsoft SharePoint Server 2019. The write-up described the vulnerable code path in Microsoft.SharePoint.dll and exploitation via attacker-controlled BCSOData headers.
Microsoft informed the researchers that the SharePoint Server 2019 SSRF vulnerability had been fixed. The issue reportedly affected versions up to 16.0.10386.20011 and did not receive a CVE identifier.
STAR Labs disclosed a post-authentication SSRF vulnerability in Microsoft SharePoint Server 2019 to Microsoft. The flaw affected the ExecuteRemoteLOB endpoint and allowed authenticated users to send customizable HTTP(S) requests to arbitrary URLs and read 2xx responses.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.