MicroStrategy hat zwischenzeitlich ebenfalls bestätigt, dass gewisse Versionen Ihrer BI-Lösung von der aktuellen Sicherheitslücke betroffen sein können.
Konkret schreibt MicroStrategy dazu:
MicroStrategy was made aware of a new vulnerability which affects the Java Spring Framework (CVE-2022-22965) on March 30, 2022. Since then, the MicroStrategy Technical Support teams have worked diligently to ensure that your enterprise receives all the necessary support and mitigation documentation.
At this time, we would like to share the below detailed communication which outlines our response and plan forward for the Java Spring vulnerability. We invite you to read it carefully and welcome any questions you may have.....
und weiter
MicroStrategy immediately mobilized its teams to understand and remediate any exposures that the MicroStrategy application might have to this vulnerability. MicroStrategy determined impact to its products as a result of this vulnerability and has provided remediation steps.
MicroStrategy has implemented emergency configuration changes to its MicroStrategy AWS Cloud Environment (MCE) to protect its customer environments. For MicroStrategy Cloud Portal (MCP) and on-premise customers utilizing the MicroStrategy application the following Knowledge Base Article (login required) has been created to provide detailed steps for implementing the mitigation. MicroStrategy recommends all customers apply the recommended remediation steps as soon as possible.
MicroStrategy is releasing MicroStrategy 2021 Update 5.1 with the updated Spring framework library (version 5.3.18) on or before April 8, 2022. MicroStrategy recommends all customers update to the latest version of the MicroStrategy application.