CVE-2020-1018 PUBLISHED CVSS 7.5 HIGH

An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.

EPSS 3.92% · 88.2th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
3.92%
88.2th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Dynamics NAV 2015unspecified
MicrosoftMicrosoft Dynamics NAV 2018unspecified
microsoftdynamics_nav2015, 2018, 2017
MicrosoftMicrosoft Dynamics NAV 2017unspecified
MicrosoftDynamics 365 Business Central 2019 Spring Updateunspecified
microsoftdynamics_365_business_central2019
MicrosoftMicrosoft Dynamics NAV 2016unspecified
MicrosoftMicrosoft Dynamics 365 BC On Premiseunspecified

Timeline

References

Open in Interactive Console →