Vulnerabilities > Microstrategy > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-05-11 CVE-2022-29596 Path Traversal vulnerability in Microstrategy Enterprise Manager 2022
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal.
network
low complexity
microstrategy CWE-22
critical
9.8
2019-05-14 CVE-2018-6885 Path Traversal vulnerability in Microstrategy web Services
An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11.
network
low complexity
microstrategy CWE-22
critical
9.8