PT-2020-15840 · Microstrategy · Microstrategy

Published

2020-11-24

·

Updated

2020-12-02

·

CVE-2020-24815

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MicroStrategy versions 10.4, 2019 before Update 6, and 2020 before Update 2
Description A Server-Side Request Forgery (SSRF) issue affects the PDF generation, allowing authenticated users to access internal network resources or leak local system files via HTML containers in a dossier/dashboard document.
Recommendations For MicroStrategy version 10.4, as it will reach end-of-life and no fix will be released, consider upgrading to a newer version or alternative solution. For MicroStrategy 2019 before Update 6, update to Update 6 or later. For MicroStrategy 2020 before Update 2, update to Update 2 or later. As a temporary workaround, consider restricting access to the PDF generation feature or disabling the embedding of HTML containers in dossier/dashboard documents until a patch is available.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24815

Affected Products

Microstrategy