CVE-2020-11450
MicroStrategy Web 10.4 - Information Disclosure
Record summary
CVE-2020-11450 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp. An attacker could use this vulnerability to learn more about the environment the application is running in. This issue has been mitigated in all versions of the product 11.0 and higher.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHMicroStrategy Web 10.4 - Information DisclosureCVSS 7.5
MicroStrategy Web 10.4 is susceptible to information disclosure. The JVM configuration, CPU architecture, installation folder, and other information are exposed through /MicroStrategyWS/happyaxis.jsp. An attacker can use this vulnerability to learn more about the application environment and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to gain sensitive information.
Remediation
Mitigated in all versions 11.0 and higher.
Source: ProjectDiscovery