Перейти к содержимому
Noroxi

Записи microstrategy

20 опубликованных записей вендора microstrategy.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

20 записей
  • CVE-2022-29596
    40В плане

    MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    microstrategy · enterprise manager11 мая 2022 г.

  • CVE-2018-6885
    39Наблюдать

    An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    microstrategy · web services14 мая 2019 г.

  • CVE-2020-11450
    35Наблюдать

    Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStr

    ВысокаяCVSS 7,5Proof of conceptEPSS 18 %

    microstrategy · microstrategy web2 апр. 2020 г.

  • CVE-2018-18696
    35Наблюдать

    main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    microstrategy · microstrategy28 дек. 2018 г.

  • CVE-2020-22983
    33Наблюдать

    A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    microstrategy · microstrategy web13 мая 2022 г.

  • CVE-2020-11451
    29Наблюдать

    The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files w

    ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %

    microstrategy · microstrategy web2 апр. 2020 г.

  • CVE-2020-24815
    27Наблюдать

    A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allo

    СредняяCVSS 6,5Proof of conceptEPSS 2 %

    microstrategy · microstrategy24 нояб. 2020 г.

  • CVE-2018-18775
    26Наблюдать

    Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v

    СредняяCVSS 6,1Proof of conceptEPSS 8 %

    microstrategy · microstrategy web1 нояб. 2018 г.

  • CVE-2019-18957
    25Наблюдать

    Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.

    СредняяCVSS 6,1Proof of conceptEPSS 5 %

    microstrategy · microstrategy library14 нояб. 2019 г.

  • CVE-2018-18776
    25Наблюдать

    Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    microstrategy · microstrategy web1 нояб. 2018 г.

  • CVE-2018-18777
    24Наблюдать

    Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote a

    СредняяCVSS 4,3Proof of conceptEPSS 23 %

    microstrategy · microstrategy web1 нояб. 2018 г.

  • CVE-2020-22985
    24Наблюдать

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    microstrategy · microstrategy web sdk12 мая 2022 г.

  • CVE-2020-22984
    24Наблюдать

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    microstrategy · microstrategy web sdk12 мая 2022 г.

  • CVE-2020-22986
    24Наблюдать

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    microstrategy · microstrategy web sdk12 мая 2022 г.

  • CVE-2020-22987
    24Наблюдать

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    microstrategy · microstrategy web sdk12 мая 2022 г.

  • CVE-2019-12453
    24Наблюдать

    In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    microstrategy · microstrategy web19 июл. 2019 г.

  • CVE-2019-12475
    24Наблюдать

    In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    microstrategy · microstrategy web17 июл. 2019 г.

  • CVE-2020-11453
    22Наблюдать

    Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStr

    СредняяCVSS 5,3Эксплойта нетEPSS 3 %

    microstrategy · microstrategy web2 апр. 2020 г.

  • CVE-2020-11454
    21Наблюдать

    Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation o

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    microstrategy · microstrategy web2 апр. 2020 г.

  • CVE-2020-11452
    17Наблюдать

    Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases.

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    microstrategy · microstrategy web2 апр. 2020 г.