Record summary

CVE-2020-11450 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp. An attacker could use this vulnerability to learn more about the environment the application is running in. This issue has been mitigated in all versions of the product 11.0 and higher.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHMicroStrategy Web 10.4 - Information DisclosureCVSS 7.5

MicroStrategy Web 10.4 is susceptible to information disclosure. The JVM configuration, CPU architecture, installation folder, and other information are exposed through /MicroStrategyWS/happyaxis.jsp. An attacker can use this vulnerability to learn more about the application environment and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to gain sensitive information.

Remediation

Mitigated in all versions 11.0 and higher.

Authorstess
Template tagscve2020cvepacketstormseclistsmicrostrategyexposurejvmconfigxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:microstrategy:microstrategy_web:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5