VDB

CVE-2020-1018

CVE-2020-1018 PUBLISHED CVSS 7.5 HIGH

An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.

EPSS 3.92% · 88.5th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
3.92%
88.5th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Dynamics NAV 2015unspecified
MicrosoftMicrosoft Dynamics NAV 2018unspecified
microsoftdynamics_nav2015, 2018, 2016
MicrosoftMicrosoft Dynamics NAV 2017*
MicrosoftDynamics 365 Business Central 2019 Spring Updateunspecified
microsoftdynamics_365_business_central2019
MicrosoftMicrosoft Dynamics NAV 2016unspecified
MicrosoftMicrosoft Dynamics 365 BC On Premise*

Timeline

  • Apr 15, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›