CVE-2020-1018High

Microsoft Dynamics Business Central/NAV Information Disclosure

Published
April 14, 2020
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page. The attacker who successfully exploited the vulnerability could see the information that are in a masked field. The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked.

🎯 Affected products6

  • Dynamics 365 Business Central 2019 Spring Update
  • Microsoft Dynamics 365 BC On Premise
  • Microsoft Dynamics NAV 2015
  • Microsoft Dynamics NAV 2016
  • Microsoft Dynamics NAV 2017
  • Microsoft Dynamics NAV 2018

✅ Remediation

KB4549673 (Security Update) KB4549674 (Security Update) KB4549675 (Security Update) KB4557700 (Security Update) KB4549676 (Security Update) KB4549677 (Security Update)

🔗 References (7)