Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
What type of information could be disclosed by this vulnerability? Exploiting this vulnerability could allow the disclosure of credentials. What action should customers using Microsoft Dynamics 365 Business Central 2024 Release Wave 2 (version 25.x) take? Version 25.x has reached the end of support and will not receive a security update for this vulnerability. Customers should upgrade to version 26.14 or later; see the Dynamics 365 Business Central on-premises lifecycle policy and KB 5100263 for more information.
<a href="https://www.linkedin.com/in/nhienit/">nhienit</a> with <a href="https://galaxy.one/">Galaxy One</a>