← Back

CVE-2018-6885

nvd nist
Published: May 14, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11. The vulnerability is unauthenticated and leads to access to the asset files with the MicroStrategy user privileges. (This includes the credentials to access the admin dashboard which may lead to RCE.) The path traversal is located in a SOAP request in the web service component.

Affected (9)

1 product
Web Services
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Microstrategy
Before 10.4
From 10.5 to 10.11
Version 10.4
Version 10.4 hotfix_1
Version 10.4 hotfix_2
Version 10.4 hotfix_3
Version 10.4 hotfix_4
Version 10.4 hotfix_5
Version 10.4 hotfix_6

References (2)

Timeline

No history available yet.