Learn about CVE-2018-6885, a security concern in MicroStrategy Web Services allowing unauthorized access to asset files and potential remote code execution. Find mitigation steps and preventive measures here.
A security concern was identified in MicroStrategy Web Services, specifically the Microsoft Office plugin, allowing unauthorized access to asset files and potentially leading to remote code execution.
Understanding CVE-2018-6885
What is CVE-2018-6885?
An issue in MicroStrategy Web Services (Microsoft Office plugin) before versions 10.4 Hotfix 7 and 10.11 allows unauthorized access to asset files using the MicroStrategy user's privileges, potentially leading to remote code execution.
The Impact of CVE-2018-6885
The vulnerability enables attackers to gain access to admin dashboard credentials, posing a risk of unauthorized access and potential remote code execution.
Technical Details of CVE-2018-6885
Vulnerability Description
The vulnerability is a path traversal issue within a SOAP request of the web service component, allowing unauthorized access to asset files.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates