CVE-2020-1018
Summary
| CVE | CVE-2020-1018 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-15 15:15:00 UTC |
| Updated | 2020-04-22 14:30:00 UTC |
| Description | An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Dynamics 365 Business Central | - | All | All | All |
| Application | Microsoft | Dynamics 365 Business Central | 2019 | spring_update | All | All |
| Application | Microsoft | Dynamics 365 Business Central | - | All | All | All |
| Application | Microsoft | Dynamics 365 Business Central | 2019 | spring_update | All | All |
| Application | Microsoft | Dynamics Nav | 2015 | All | All | All |
| Application | Microsoft | Dynamics Nav | 2016 | All | All | All |
| Application | Microsoft | Dynamics Nav | 2017 | All | All | All |
| Application | Microsoft | Dynamics Nav | 2018 | All | All | All |
| Application | Microsoft | Dynamics Nav | 2015 | All | All | All |
| Application | Microsoft | Dynamics Nav | 2016 | All | All | All |
| Application | Microsoft | Dynamics Nav | 2017 | All | All | All |
| Application | Microsoft | Dynamics Nav | 2018 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| N/A | N/A | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.