microstrategy kayıtları
microstrategy üreticisine ait 20 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
20 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-29596İstismar yok | MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../.microstrategy · enterprise manager · CWE-22 | Kritik9,8 | — | %2,1 | 11 May 2022 |
39İzleyin | CVE-2018-6885İstismar yok | An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.microstrategy · web services · CWE-22 | Kritik9,8 | — | %1,4 | 14 May 2019 |
35İzleyin | CVE-2020-11450Kavram kanıtı | Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrmicrostrategy · microstrategy web | Yüksek7,5 | — | %17,8 | 2 Nis 2020 |
35İzleyin | CVE-2018-18696İstismar yok | main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF.microstrategy · microstrategy · CWE-352 | Yüksek8,8 | — | %0,8 | 28 Ara 2018 |
33İzleyin | CVE-2020-22983İstismar yok | A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackersmicrostrategy · microstrategy web · CWE-918 | Yüksek8,1 | — | %2,4 | 13 May 2022 |
29İzleyin | CVE-2020-11451İstismar yok | The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files wmicrostrategy · microstrategy web · CWE-434 | Yüksek7,2 | — | %2,7 | 2 Nis 2020 |
27İzleyin | CVE-2020-24815Kavram kanıtı | A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allomicrostrategy · microstrategy · CWE-918 | Orta6,5 | — | %1,8 | 24 Kas 2020 |
26İzleyin | CVE-2018-18775Kavram kanıtı | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability vmicrostrategy · microstrategy web · CWE-79 | Orta6,1 | — | %7,9 | 1 Kas 2018 |
25İzleyin | CVE-2019-18957Kavram kanıtı | Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.microstrategy · microstrategy library · CWE-79 | Orta6,1 | — | %4,9 | 14 Kas 2019 |
25İzleyin | CVE-2018-18776Kavram kanıtı | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability vmicrostrategy · microstrategy web · CWE-79 | Orta6,1 | — | %2,3 | 1 Kas 2018 |
24İzleyin | CVE-2018-18777Kavram kanıtı | Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote amicrostrategy · microstrategy web · CWE-22 | Orta4,3 | — | %22,8 | 1 Kas 2018 |
24İzleyin | CVE-2020-22985İstismar yok | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Orta6,1 | — | %1,6 | 12 May 2022 |
24İzleyin | CVE-2020-22984İstismar yok | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Orta6,1 | — | %1,6 | 12 May 2022 |
24İzleyin | CVE-2020-22986İstismar yok | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Orta6,1 | — | %1,6 | 12 May 2022 |
24İzleyin | CVE-2020-22987İstismar yok | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbimicrostrategy · microstrategy web sdk · CWE-79 | Orta6,1 | — | %1,5 | 12 May 2022 |
24İzleyin | CVE-2019-12453Kavram kanıtı | In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.microstrategy · microstrategy web · CWE-79 | Orta6,1 | — | %1,0 | 19 Tem 2019 |
24İzleyin | CVE-2019-12475Kavram kanıtı | In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.microstrategy · microstrategy web · CWE-79 | Orta6,1 | — | %1,0 | 17 Tem 2019 |
22İzleyin | CVE-2020-11453İstismar yok | Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrmicrostrategy · microstrategy web · CWE-918 | Orta5,3 | — | %2,7 | 2 Nis 2020 |
21İzleyin | CVE-2020-11454İstismar yok | Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation omicrostrategy · microstrategy web · CWE-79 | Orta5,4 | — | %0,9 | 2 Nis 2020 |
17İzleyin | CVE-2020-11452İstismar yok | Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases.microstrategy · microstrategy web · CWE-918 | Orta4,3 | — | %1,2 | 2 Nis 2020 |
- CVE-2022-2959640Planlayın
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../.
KritikCVSS 9,8İstismar yokEPSS %2microstrategy · enterprise manager11 May 2022
- CVE-2018-688539İzleyin
An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.
KritikCVSS 9,8İstismar yokEPSS %1microstrategy · web services14 May 2019
- CVE-2020-1145035İzleyin
Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStr
YüksekCVSS 7,5Kavram kanıtıEPSS %18microstrategy · microstrategy web2 Nis 2020
- CVE-2018-1869635İzleyin
main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1microstrategy · microstrategy28 Ara 2018
- CVE-2020-2298333İzleyin
A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers
YüksekCVSS 8,1İstismar yokEPSS %2microstrategy · microstrategy web13 May 2022
- CVE-2020-1145129İzleyin
The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files w
YüksekCVSS 7,2İstismar yokEPSS %3microstrategy · microstrategy web2 Nis 2020
- CVE-2020-2481527İzleyin
A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allo
OrtaCVSS 6,5Kavram kanıtıEPSS %2microstrategy · microstrategy24 Kas 2020
- CVE-2018-1877526İzleyin
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v
OrtaCVSS 6,1Kavram kanıtıEPSS %8microstrategy · microstrategy web1 Kas 2018
- CVE-2019-1895725İzleyin
Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.
OrtaCVSS 6,1Kavram kanıtıEPSS %5microstrategy · microstrategy library14 Kas 2019
- CVE-2018-1877625İzleyin
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability v
OrtaCVSS 6,1Kavram kanıtıEPSS %2microstrategy · microstrategy web1 Kas 2018
- CVE-2018-1877724İzleyin
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote a
OrtaCVSS 4,3Kavram kanıtıEPSS %23microstrategy · microstrategy web1 Kas 2018
- CVE-2020-2298524İzleyin
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
OrtaCVSS 6,1İstismar yokEPSS %2microstrategy · microstrategy web sdk12 May 2022
- CVE-2020-2298424İzleyin
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
OrtaCVSS 6,1İstismar yokEPSS %2microstrategy · microstrategy web sdk12 May 2022
- CVE-2020-2298624İzleyin
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
OrtaCVSS 6,1İstismar yokEPSS %2microstrategy · microstrategy web sdk12 May 2022
- CVE-2020-2298724İzleyin
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbi
OrtaCVSS 6,1İstismar yokEPSS %1microstrategy · microstrategy web sdk12 May 2022
- CVE-2019-1245324İzleyin
In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.
OrtaCVSS 6,1Kavram kanıtıEPSS %1microstrategy · microstrategy web19 Tem 2019
- CVE-2019-1247524İzleyin
In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.
OrtaCVSS 6,1Kavram kanıtıEPSS %1microstrategy · microstrategy web17 Tem 2019
- CVE-2020-1145322İzleyin
Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStr
OrtaCVSS 5,3İstismar yokEPSS %3microstrategy · microstrategy web2 Nis 2020
- CVE-2020-1145421İzleyin
Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation o
OrtaCVSS 5,4İstismar yokEPSS %1microstrategy · microstrategy web2 Nis 2020
- CVE-2020-1145217İzleyin
Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases.
OrtaCVSS 4,3İstismar yokEPSS %1microstrategy · microstrategy web2 Nis 2020