Microstrategy's vulnerability footprint concentrates in a narrow portfolio of business-intelligence and analytics products, notably its web-facing platform and SDK components, that serve as data-visualization and reporting engines in enterprise environments. The exposure recurs through web-application-oriented weakness classes including cross-site scripting, server-side request forgery, path traversal, and cross-site request forgery, reflecting the complexity of parsing user input and managing web-session state in large analytics platforms. A meaningful share of the vendor's disclosures reach serious severity, and the profile shows an elevated tendency toward public exploit availability, making timely patching of internet-accessible instances a priority for defenders. The vulnerability patterns are characteristic of middleware and application-tier software rather than core infrastructure, and they concentrate in the web and SDK layers where user-controlled input interacts with backend data access. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microstrategy over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18777MEDIUM Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended Se | Nov 1, 2018 | 4.3 | 44 | NO | YES |
CVE-2018-18775MEDIUM Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: t | Nov 1, 2018 | 6.1 | 41 | NO | YES |
CVE-2020-11450HIGH Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp. An attacker could | Apr 2, 2020 | 7.5 | 37 | NO | YES |
CVE-2019-18957MEDIUM Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS. | Nov 14, 2019 | 6.1 | 31 | NO | YES |
CVE-2018-18776MEDIUM Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter | Nov 1, 2018 | 6.1 | 31 | NO | YES |
CVE-2022-29596CRITICAL MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg& | May 11, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-22983HIGH A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forger | May 13, 2022 | 8.1 | 29 | NO | NO |
CVE-2018-6885CRITICAL An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11. The vulnerability is unauthenticated and leads to access | May 14, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-18696HIGH main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://communi | Dec 28, 2018 | 8.8 | 27 | NO | NO |
CVE-2020-22987MEDIUM Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload paramete | May 12, 2022 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microstrategy.
Media articles that mention a CVE ID that affects a product developed by Microstrategy — matched by CVE ID, not by vendor name.