CVE-2020-1018
Last modified
CVE-2020-1018 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.. EPSS estimates a 6.16% chance of exploitation in the next 30 days.
Description
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Dynamics 365 Business Central | All versions | — |
| Microsoft | Dynamics 365 Business Central | 2019 | Spring Update |
| Microsoft | Dynamics Nav | 2015 | — |
| Microsoft | Dynamics Nav | 2016 | — |
| Microsoft | Dynamics Nav | 2017 | — |
| Microsoft | Dynamics Nav | 2018 | — |
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1018Patch, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1018Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1018?
How severe is CVE-2020-1018?
How do I fix CVE-2020-1018?
Are you affected by CVE-2020-1018?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
