CVE-2020-11450
high-risk
Published 2020-04-02
Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp. An attacker could use this vulnerability to learn more about the environment the application is running in. This issue has been mitigated in all versions of the product 11.0 and higher.
Do I need to act?
!
89.8% chance of exploitation in next 30 days
EPSS score — higher than 10% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (8)
Mailing List
http://seclists.org/fulldisclosure/2020/Apr/1
Mailing List
http://seclists.org/fulldisclosure/2020/Apr/1
51
/ 100
high-risk
Severity
26/34 · High
Exploitability
20/34 · Moderate
Exposure
5/34 · Minimal