7.5
CVSSv3

CVE-2020-11450

Published: 02/04/2020 Updated: 22/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp. An attacker could use this vulnerability to learn more about the environment the application is running in. This issue has been mitigated in all versions of the product 11.0 and higher.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microstrategy microstrategy web

Exploits

MicroStrategy Intelligence Server and Web version 104 suffers from remote code execution, cross site scripting, server-side request forgery, and information disclosure vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> MicroStrategy Intelligence Server and Web 104 - multiple vulnerabilities <!--X-Subject-Header-End--> <!--X-Head-of-Me ...