microstrategy records
20 published records for vendor microstrategy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-29596No exploit | MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../.microstrategy · enterprise manager · CWE-22 | Critical9.8 | — | 2.1% | May 11, 2022 |
39Monitor | CVE-2018-6885No exploit | An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.microstrategy · web services · CWE-22 | Critical9.8 | — | 1.4% | May 14, 2019 |
35Monitor | CVE-2020-11450Proof of concept | Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrmicrostrategy · microstrategy web | High7.5 | — | 17.8% | Apr 2, 2020 |
35Monitor | CVE-2018-18696No exploit | main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF.microstrategy · microstrategy · CWE-352 | High8.8 | — | 0.8% | Dec 28, 2018 |
33Monitor | CVE-2020-22983No exploit | A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackersmicrostrategy · microstrategy web · CWE-918 | High8.1 | — | 2.4% | May 13, 2022 |
29Monitor | CVE-2020-11451No exploit | The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files wmicrostrategy · microstrategy web · CWE-434 | High7.2 | — | 2.7% | Apr 2, 2020 |
27Monitor | CVE-2020-24815Proof of concept | A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allomicrostrategy · microstrategy · CWE-918 | Medium6.5 | — | 1.8% | Nov 24, 2020 |
26Monitor | CVE-2018-18775Proof of concept | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability vmicrostrategy · microstrategy web · CWE-79 | Medium6.1 | — | 7.9% | Nov 1, 2018 |
25Monitor | CVE-2019-18957Proof of concept | Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.microstrategy · microstrategy library · CWE-79 | Medium6.1 | — | 4.9% | Nov 14, 2019 |
25Monitor | CVE-2018-18776Proof of concept | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability vmicrostrategy · microstrategy web · CWE-79 | Medium6.1 | — | 2.3% | Nov 1, 2018 |
24Monitor | CVE-2018-18777Proof of concept | Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote amicrostrategy · microstrategy web · CWE-22 | Medium4.3 | — | 22.8% | Nov 1, 2018 |
24Monitor | CVE-2020-22985No exploit | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Medium6.1 | — | 1.6% | May 12, 2022 |
24Monitor | CVE-2020-22984No exploit | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Medium6.1 | — | 1.6% | May 12, 2022 |
24Monitor | CVE-2020-22986No exploit | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Medium6.1 | — | 1.6% | May 12, 2022 |
24Monitor | CVE-2020-22987No exploit | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Medium6.1 | — | 1.5% | May 12, 2022 |
24Monitor | CVE-2019-12453Proof of concept | In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.microstrategy · microstrategy web · CWE-79 | Medium6.1 | — | 1.0% | Jul 19, 2019 |
24Monitor | CVE-2019-12475Proof of concept | In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.microstrategy · microstrategy web · CWE-79 | Medium6.1 | — | 1.0% | Jul 17, 2019 |
22Monitor | CVE-2020-11453No exploit | Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrmicrostrategy · microstrategy web · CWE-918 | Medium5.3 | — | 2.7% | Apr 2, 2020 |
21Monitor | CVE-2020-11454No exploit | Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation omicrostrategy · microstrategy web · CWE-79 | Medium5.4 | — | 0.9% | Apr 2, 2020 |
17Monitor | CVE-2020-11452No exploit | Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases.microstrategy · microstrategy web · CWE-918 | Medium4.3 | — | 1.2% | Apr 2, 2020 |
- CVE-2022-2959640Plan
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../.
CriticalCVSS 9.8No exploitEPSS 2%microstrategy · enterprise managerMay 11, 2022
- CVE-2018-688539Monitor
An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.
CriticalCVSS 9.8No exploitEPSS 1%microstrategy · web servicesMay 14, 2019
- CVE-2020-1145035Monitor
Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStr
HighCVSS 7.5Proof of conceptEPSS 18%microstrategy · microstrategy webApr 2, 2020
- CVE-2018-1869635Monitor
main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF.
HighCVSS 8.8No exploitEPSS 1%microstrategy · microstrategyDec 28, 2018
- CVE-2020-2298333Monitor
A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers
HighCVSS 8.1No exploitEPSS 2%microstrategy · microstrategy webMay 13, 2022
- CVE-2020-1145129Monitor
The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files w
HighCVSS 7.2No exploitEPSS 3%microstrategy · microstrategy webApr 2, 2020
- CVE-2020-2481527Monitor
A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allo
MediumCVSS 6.5Proof of conceptEPSS 2%microstrategy · microstrategyNov 24, 2020
- CVE-2018-1877526Monitor
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v
MediumCVSS 6.1Proof of conceptEPSS 8%microstrategy · microstrategy webNov 1, 2018
- CVE-2019-1895725Monitor
Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.
MediumCVSS 6.1Proof of conceptEPSS 5%microstrategy · microstrategy libraryNov 14, 2019
- CVE-2018-1877625Monitor
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v
MediumCVSS 6.1Proof of conceptEPSS 2%microstrategy · microstrategy webNov 1, 2018
- CVE-2018-1877724Monitor
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote a
MediumCVSS 4.3Proof of conceptEPSS 23%microstrategy · microstrategy webNov 1, 2018
- CVE-2020-2298524Monitor
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
MediumCVSS 6.1No exploitEPSS 2%microstrategy · microstrategy web sdkMay 12, 2022
- CVE-2020-2298424Monitor
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
MediumCVSS 6.1No exploitEPSS 2%microstrategy · microstrategy web sdkMay 12, 2022
- CVE-2020-2298624Monitor
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
MediumCVSS 6.1No exploitEPSS 2%microstrategy · microstrategy web sdkMay 12, 2022
- CVE-2020-2298724Monitor
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
MediumCVSS 6.1No exploitEPSS 1%microstrategy · microstrategy web sdkMay 12, 2022
- CVE-2019-1245324Monitor
In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.
MediumCVSS 6.1Proof of conceptEPSS 1%microstrategy · microstrategy webJul 19, 2019
- CVE-2019-1247524Monitor
In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.
MediumCVSS 6.1Proof of conceptEPSS 1%microstrategy · microstrategy webJul 17, 2019
- CVE-2020-1145322Monitor
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStr
MediumCVSS 5.3No exploitEPSS 3%microstrategy · microstrategy webApr 2, 2020
- CVE-2020-1145421Monitor
Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation o
MediumCVSS 5.4No exploitEPSS 1%microstrategy · microstrategy webApr 2, 2020
- CVE-2020-1145217Monitor
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases.
MediumCVSS 4.3No exploitEPSS 1%microstrategy · microstrategy webApr 2, 2020