An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11. The vulnerability is unauthenticated and leads to access to the asset files with the MicroStrategy user privileges. (This includes the credentials to access the admin dashboard which may lead to RCE.) The path traversal is located in a SOAP request in the web service component.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-05-14T18:35:15
Updated: 2024-08-05T06:17:17.079Z
Reserved: 2018-02-10T00:00:00
Link: CVE-2018-6885
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-05-14T19:29:00.247
Modified: 2024-11-21T04:11:22.017
Link: CVE-2018-6885
Redhat
No data.