Lucene search

K

Business-central Security Vulnerabilities

cve
cve

CVE-2024-35248

Microsoft Dynamics 365 Business Central Elevation of Privilege...

7.3CVSS

7.2AI Score

0.001EPSS

2024-06-11 05:16 PM
25
cve
cve

CVE-2024-35249

Microsoft Dynamics 365 Business Central Remote Code Execution...

8.8CVSS

8.9AI Score

0.001EPSS

2024-06-11 05:16 PM
24
cve
cve

CVE-2024-21380

Microsoft Dynamics Business Central/NAV Information Disclosure...

8CVSS

8.3AI Score

0.001EPSS

2024-02-13 06:15 PM
156
cve
cve

CVE-2023-38167

Microsoft Dynamics Business Central Elevation Of Privilege...

7.2CVSS

6.9AI Score

0.0005EPSS

2023-08-08 06:15 PM
68
cve
cve

CVE-2023-31404

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could....

5CVSS

5AI Score

0.001EPSS

2023-05-09 02:15 AM
27
cve
cve

CVE-2023-0018

Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload. Once these reports are viewable,....

10CVSS

5.9AI Score

0.001EPSS

2023-01-10 04:15 AM
34
cve
cve

CVE-2022-41127

Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution...

8.5CVSS

8.6AI Score

0.006EPSS

2022-12-13 07:15 PM
72
cve
cve

CVE-2022-41066

Microsoft Business Central Information Disclosure...

4.4CVSS

4.3AI Score

0.004EPSS

2022-11-09 10:15 PM
44
2
cve
cve

CVE-2022-41203

In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can intercept a serialized object in the parameters and substitute with another malicious serialized object, which leads to deserialization of untrusted.....

8.8CVSS

8.6AI Score

0.001EPSS

2022-11-08 10:15 PM
66
3
cve
cve

CVE-2019-14841

A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central...

8.8CVSS

8.6AI Score

0.001EPSS

2022-10-17 04:15 PM
26
3
cve
cve

CVE-2019-14840

A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of...

7.5CVSS

7.2AI Score

0.002EPSS

2022-10-17 04:15 PM
22
3
cve
cve

CVE-2022-35228

SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful....

8.8CVSS

8.3AI Score

0.001EPSS

2022-07-12 09:15 PM
33
3
cve
cve

CVE-2022-28214

During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-05-11 03:15 PM
48
3
cve
cve

CVE-2019-14839

It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite...

7.5CVSS

7.5AI Score

0.002EPSS

2022-04-01 11:15 PM
36
cve
cve

CVE-2021-45105

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue...

5.9CVSS

7.5AI Score

0.966EPSS

2021-12-18 12:15 PM
752
In Wild
4
cve
cve

CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message....

10CVSS

9.8AI Score

0.976EPSS

2021-12-10 10:15 AM
3635
In Wild
399
cve
cve

CVE-2021-40440

Microsoft Dynamics Business Central Cross-site Scripting...

5.4CVSS

5.4AI Score

0.001EPSS

2021-09-15 12:15 PM
51
cve
cve

CVE-2021-36946

Microsoft Dynamics Business Central Cross-site Scripting...

5.4CVSS

5.7AI Score

0.001EPSS

2021-08-12 06:15 PM
85
cve
cve

CVE-2021-34474

Dynamics Business Central Remote Code Execution...

8CVSS

7.9AI Score

0.014EPSS

2021-07-14 06:15 PM
81
2
cve
cve

CVE-2021-20306

A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerability is to...

4.3CVSS

4.3AI Score

0.001EPSS

2021-06-01 02:15 PM
45
4
cve
cve

CVE-2021-25252

Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted...

5.5CVSS

5.4AI Score

0.0004EPSS

2021-03-03 04:15 PM
32
cve
cve

CVE-2021-1724

Microsoft Dynamics Business Central Cross-site Scripting...

6.1CVSS

5.9AI Score

0.001EPSS

2021-02-25 11:15 PM
55
2
cve
cve

CVE-2020-6300

SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not sufficiently encode user-controlled inputs for...

4.8CVSS

4.9AI Score

0.001EPSS

2020-08-12 02:15 PM
24
cve
cve

CVE-2020-1945

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build...

6.3CVSS

6.8AI Score

0.001EPSS

2020-05-14 04:15 PM
355
5
cve
cve

CVE-2020-1022

A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution...

8CVSS

8AI Score

0.024EPSS

2020-04-15 03:15 PM
54
cve
cve

CVE-2020-1018

An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a...

7.5CVSS

7AI Score

0.013EPSS

2020-04-15 03:15 PM
77
cve
cve

CVE-2020-0905

An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution...

8CVSS

8AI Score

0.024EPSS

2020-03-12 04:15 PM
74
cve
cve

CVE-2019-14886

A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user...

6.5CVSS

6.3AI Score

0.001EPSS

2020-03-05 06:15 PM
59
4
cve
cve

CVE-2019-10219

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS...

6.1CVSS

6AI Score

0.002EPSS

2019-11-08 03:15 PM
169
6
cve
cve

CVE-2019-0287

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be...

7.6CVSS

7.3AI Score

0.005EPSS

2019-05-14 09:29 PM
31
cve
cve

CVE-2019-11358

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native...

6.1CVSS

6.4AI Score

0.035EPSS

2019-04-20 12:29 AM
1198
In Wild
6
cve
cve

CVE-2017-2674

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not....

6.1CVSS

5.2AI Score

0.025EPSS

2018-07-27 06:29 PM
31
cve
cve

CVE-2017-7463

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of...

6.1CVSS

6.1AI Score

0.002EPSS

2018-07-27 06:29 PM
39
cve
cve

CVE-2018-2432

SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including:.....

5.4CVSS

5.2AI Score

0.001EPSS

2018-07-10 06:29 PM
25
cve
cve

CVE-2018-8013

In Apache Batik 1.x before 1.10, when deserializing subclass of AbstractDocument, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in...

9.8CVSS

8.6AI Score

0.006EPSS

2018-05-24 04:29 PM
124