- Description
- A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML containers embedded in a dossier/dashboard document. NOTE: 10.4., no fix will be released as version will reach end-of-life on 31/12/2020.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
- nvd@nist.gov
- CWE-918
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microstrategy:microstrategy:10.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89A36A18-107F-4BE8-AAD9-EDECB714188D"
},
{
"criteria": "cpe:2.3:a:microstrategy:microstrategy:2019:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDC2C780-0996-4D8A-A4B1-461B442A7089"
},
{
"criteria": "cpe:2.3:a:microstrategy:microstrategy:2019:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89F1B5AF-677F-4B90-AD13-F8CE8588ED0C"
},
{
"criteria": "cpe:2.3:a:microstrategy:microstrategy:2019:update3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4DE22024-C6A9-4547-8712-7C5B8F1ED5A2"
},
{
"criteria": "cpe:2.3:a:microstrategy:microstrategy:2019:update4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E74CDB4D-5034-48A8-9AD9-1DD5D363D180"
},
{
"criteria": "cpe:2.3:a:microstrategy:microstrategy:2019:update5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4FA72CA6-485D-4564-A265-70D90032FBFA"
},
{
"criteria": "cpe:2.3:a:microstrategy:microstrategy:2020:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F59AFCFE-AC0E-4B6E-8576-2C1553F8CA76"
}
],
"operator": "OR"
}
]
}
]