CVE-2020-17133: Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Dec
Released
2020-12-08
EPSS Score
12.08% (percentile: 93.8%)

FAQ

What privileges are required to exploit this vulnerability? To exploit this vulnerability, an attacker would have to be present in the tenant as a system user.

Affected Products (1)

Microsoft Dynamics

  • Microsoft Dynamics NAV 2015

Security Updates (1)

Revision History

  • 2020-12-08: Information published.