Vulnerability Description
An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11. The vulnerability is unauthenticated and leads to access to the asset files with the MicroStrategy user privileges. (This includes the credentials to access the admin dashboard which may lead to RCE.) The path traversal is located in a SOAP request in the web service component.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microstrategy | Web Services | < 10.4 |
Related Weaknesses (CWE)
References
- https://community.microstrategy.com/s/article/Web-Services-Security-VulnerabilitVendor Advisory
- https://community.microstrategy.com/s/article/Web-Services-Security-VulnerabilitVendor Advisory
FAQ
What is CVE-2018-6885?
CVE-2018-6885 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11. The vulnerability is unauthenticated and leads to access to the asset files ...
How severe is CVE-2018-6885?
CVE-2018-6885 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-6885?
Check the references section above for vendor advisories and patch information. Affected products include: Microstrategy Web Services.