Записи microstrategy
20 опубликованных записей вендора microstrategy.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
20 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-29596Эксплойта нет | MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../.microstrategy · enterprise manager · CWE-22 | Критическая9,8 | — | 2,1 % | 11 мая 2022 г. |
39Наблюдать | CVE-2018-6885Эксплойта нет | An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.microstrategy · web services · CWE-22 | Критическая9,8 | — | 1,4 % | 14 мая 2019 г. |
35Наблюдать | CVE-2020-11450Proof of concept | Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrmicrostrategy · microstrategy web | Высокая7,5 | — | 17,8 % | 2 апр. 2020 г. |
35Наблюдать | CVE-2018-18696Эксплойта нет | main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF.microstrategy · microstrategy · CWE-352 | Высокая8,8 | — | 0,8 % | 28 дек. 2018 г. |
33Наблюдать | CVE-2020-22983Эксплойта нет | A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackersmicrostrategy · microstrategy web · CWE-918 | Высокая8,1 | — | 2,4 % | 13 мая 2022 г. |
29Наблюдать | CVE-2020-11451Эксплойта нет | The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files wmicrostrategy · microstrategy web · CWE-434 | Высокая7,2 | — | 2,7 % | 2 апр. 2020 г. |
27Наблюдать | CVE-2020-24815Proof of concept | A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allomicrostrategy · microstrategy · CWE-918 | Средняя6,5 | — | 1,8 % | 24 нояб. 2020 г. |
26Наблюдать | CVE-2018-18775Proof of concept | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability vmicrostrategy · microstrategy web · CWE-79 | Средняя6,1 | — | 7,9 % | 1 нояб. 2018 г. |
25Наблюдать | CVE-2019-18957Proof of concept | Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.microstrategy · microstrategy library · CWE-79 | Средняя6,1 | — | 4,9 % | 14 нояб. 2019 г. |
25Наблюдать | CVE-2018-18776Proof of concept | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability vmicrostrategy · microstrategy web · CWE-79 | Средняя6,1 | — | 2,3 % | 1 нояб. 2018 г. |
24Наблюдать | CVE-2018-18777Proof of concept | Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote amicrostrategy · microstrategy web · CWE-22 | Средняя4,3 | — | 22,8 % | 1 нояб. 2018 г. |
24Наблюдать | CVE-2020-22985Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Средняя6,1 | — | 1,6 % | 12 мая 2022 г. |
24Наблюдать | CVE-2020-22984Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Средняя6,1 | — | 1,6 % | 12 мая 2022 г. |
24Наблюдать | CVE-2020-22986Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Средняя6,1 | — | 1,6 % | 12 мая 2022 г. |
24Наблюдать | CVE-2020-22987Эксплойта нет | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Средняя6,1 | — | 1,5 % | 12 мая 2022 г. |
24Наблюдать | CVE-2019-12453Proof of concept | In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.microstrategy · microstrategy web · CWE-79 | Средняя6,1 | — | 1,0 % | 19 июл. 2019 г. |
24Наблюдать | CVE-2019-12475Proof of concept | In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.microstrategy · microstrategy web · CWE-79 | Средняя6,1 | — | 1,0 % | 17 июл. 2019 г. |
22Наблюдать | CVE-2020-11453Эксплойта нет | Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrmicrostrategy · microstrategy web · CWE-918 | Средняя5,3 | — | 2,7 % | 2 апр. 2020 г. |
21Наблюдать | CVE-2020-11454Эксплойта нет | Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation omicrostrategy · microstrategy web · CWE-79 | Средняя5,4 | — | 0,9 % | 2 апр. 2020 г. |
17Наблюдать | CVE-2020-11452Эксплойта нет | Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases.microstrategy · microstrategy web · CWE-918 | Средняя4,3 | — | 1,2 % | 2 апр. 2020 г. |
- CVE-2022-2959640В плане
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microstrategy · enterprise manager11 мая 2022 г.
- CVE-2018-688539Наблюдать
An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microstrategy · web services14 мая 2019 г.
- CVE-2020-1145035Наблюдать
Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStr
ВысокаяCVSS 7,5Proof of conceptEPSS 18 %microstrategy · microstrategy web2 апр. 2020 г.
- CVE-2018-1869635Наблюдать
main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microstrategy · microstrategy28 дек. 2018 г.
- CVE-2020-2298333Наблюдать
A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %microstrategy · microstrategy web13 мая 2022 г.
- CVE-2020-1145129Наблюдать
The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files w
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %microstrategy · microstrategy web2 апр. 2020 г.
- CVE-2020-2481527Наблюдать
A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allo
СредняяCVSS 6,5Proof of conceptEPSS 2 %microstrategy · microstrategy24 нояб. 2020 г.
- CVE-2018-1877526Наблюдать
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v
СредняяCVSS 6,1Proof of conceptEPSS 8 %microstrategy · microstrategy web1 нояб. 2018 г.
- CVE-2019-1895725Наблюдать
Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.
СредняяCVSS 6,1Proof of conceptEPSS 5 %microstrategy · microstrategy library14 нояб. 2019 г.
- CVE-2018-1877625Наблюдать
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v
СредняяCVSS 6,1Proof of conceptEPSS 2 %microstrategy · microstrategy web1 нояб. 2018 г.
- CVE-2018-1877724Наблюдать
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote a
СредняяCVSS 4,3Proof of conceptEPSS 23 %microstrategy · microstrategy web1 нояб. 2018 г.
- CVE-2020-2298524Наблюдать
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
СредняяCVSS 6,1Эксплойта нетEPSS 2 %microstrategy · microstrategy web sdk12 мая 2022 г.
- CVE-2020-2298424Наблюдать
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
СредняяCVSS 6,1Эксплойта нетEPSS 2 %microstrategy · microstrategy web sdk12 мая 2022 г.
- CVE-2020-2298624Наблюдать
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
СредняяCVSS 6,1Эксплойта нетEPSS 2 %microstrategy · microstrategy web sdk12 мая 2022 г.
- CVE-2020-2298724Наблюдать
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
СредняяCVSS 6,1Эксплойта нетEPSS 1 %microstrategy · microstrategy web sdk12 мая 2022 г.
- CVE-2019-1245324Наблюдать
In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.
СредняяCVSS 6,1Proof of conceptEPSS 1 %microstrategy · microstrategy web19 июл. 2019 г.
- CVE-2019-1247524Наблюдать
In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.
СредняяCVSS 6,1Proof of conceptEPSS 1 %microstrategy · microstrategy web17 июл. 2019 г.
- CVE-2020-1145322Наблюдать
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStr
СредняяCVSS 5,3Эксплойта нетEPSS 3 %microstrategy · microstrategy web2 апр. 2020 г.
- CVE-2020-1145421Наблюдать
Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation o
СредняяCVSS 5,4Эксплойта нетEPSS 1 %microstrategy · microstrategy web2 апр. 2020 г.
- CVE-2020-1145217Наблюдать
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %microstrategy · microstrategy web2 апр. 2020 г.