CVE-2023-21806: Power BI Report Server Spoofing Vulnerability
Published Feb 14, 2023
·Updated
Power BI Report Server Spoofing Vulnerability
Affected Software
2 affected componentsFixes available
Microsoft Power BI Report Server<15.0.1111.115
Microsoft Power BI Report Server - January 2023<1.16.8420.13742
1.16.8420.13742
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.16.8420.13742Patch KB5023884
Event History
Feb 14, 2023
CVE Published
via Microsoft·04:00 PM
Data Sourced
via Microsoft·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:00 PM
Affected Software
Updated
via Microsoft·04:00 PM
Description
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionSeverity
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-21806?
CVE-2023-21806 is classified as a spoofing vulnerability in Microsoft Power BI Report Server.
2
How do I fix CVE-2023-21806?
To fix CVE-2023-21806, you should apply the relevant security patches provided by Microsoft.
3
Which versions of Microsoft Power BI Report Server are affected by CVE-2023-21806?
CVE-2023-21806 affects Microsoft Power BI Report Server versions up to 15.0.1111.115.
4
What type of attack does CVE-2023-21806 allow?
CVE-2023-21806 allows an attacker to spoof a server and potentially compromise user data.
5
Is there a mitigation for CVE-2023-21806?
The primary mitigation for CVE-2023-21806 is to ensure that the software is updated and patched to the latest version.