Microsoft Power Bi Report Server
Recent Microsoft Power Bi Report Server Security Advisories
Advisory | Title | Published |
---|---|---|
CVE-2023-21806 | Power BI Report Server Spoofing Vulnerability | February 14, 2023 |
CVE-2021-41372 | Power BI Report Server Spoofing Vulnerability | November 9, 2021 |
By the Year
In 2023 there have been 1 vulnerability in Microsoft Power Bi Report Server with an average score of 8.2 out of ten. Power Bi Report Server did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2023 as compared to last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2023 | 1 | 8.20 |
2022 | 0 | 0.00 |
2021 | 3 | 8.30 |
2020 | 1 | 6.80 |
2019 | 1 | 6.10 |
2018 | 0 | 0.00 |
It may take a day or so for new Power Bi Report Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Power Bi Report Server Security Vulnerabilities
Power BI Report Server Spoofing Vulnerability
CVE-2023-21806
8.2 - High
- February 14, 2023
Power BI Report Server Spoofing Vulnerability
Power BI Report Server Spoofing Vulnerability
CVE-2021-41372
9.6 - Critical
- November 10, 2021
Power BI Report Server Spoofing Vulnerability
Session Riding
Power BI Remote Code Execution Vulnerability
CVE-2021-31984
8.8 - High
- July 14, 2021
Power BI Remote Code Execution Vulnerability
Microsoft Power BI Information Disclosure Vulnerability
CVE-2021-26859
6.5 - Medium
- March 11, 2021
Microsoft Power BI Information Disclosure Vulnerability
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments
CVE-2020-1173
6.8 - Medium
- May 21, 2020
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.
Improper Input Validation
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server
CVE-2019-1332
6.1 - Medium
- December 10, 2019
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Sql Server 2019 Reporting Services or by Microsoft? Click the Watch button to subscribe.
