PT-2020-12616 · Microstrategy · Microstrategy Web

Published

2020-04-02

·

Updated

2022-04-22

·

CVE-2020-11450

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microstrategy Web versions prior to 11.0
Description The issue exposes sensitive information such as JVM configuration, CPU architecture, and installation folder through the API endpoint "/MicroStrategyWS/happyaxis.jsp". This could allow an attacker to gather details about the environment the application is running in.
Recommendations For versions prior to 11.0, update to version 11.0 or higher to mitigate the issue. As a temporary workaround, consider restricting access to the "/MicroStrategyWS/happyaxis.jsp" API endpoint until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-11450

Affected Products

Microstrategy Web