Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2019-14839

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
Attacker Value
Unknown

CVE-2021-45105

Disclosure Date: December 18, 2021 (last updated October 07, 2023)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Attacker Value
Unknown

CVE-2021-40440

Disclosure Date: September 15, 2021 (last updated November 28, 2024)
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
0
Attacker Value
Unknown

CVE-2021-36946

Disclosure Date: August 12, 2021 (last updated November 28, 2024)
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
0
Attacker Value
Unknown

CVE-2021-34474

Disclosure Date: July 14, 2021 (last updated November 28, 2024)
Dynamics Business Central Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2021-25252

Disclosure Date: March 03, 2021 (last updated November 28, 2024)
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
Attacker Value
Unknown

CVE-2021-1724

Disclosure Date: February 25, 2021 (last updated November 28, 2024)
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
0
Attacker Value
Unknown

CVE-2020-1945

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
Attacker Value
Unknown

CVE-2020-1018

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.
Attacker Value
Unknown

CVE-2020-1022

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.