Vulnerabilities
Vulnerable Software
Microsoft:  >> Dynamics 365  >> 9.0  Security Vulnerabilities
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.
CVSS Score
5.4
EPSS Score
0.01
Published
2019-10-10
An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer privilege within Dynamics to gain control of the Web Role hosting the Dynamics installation. To exploit this vulnerability, an attacker needs to have credentials for a user that has permission to author customized business rules in Dynamics, and persist XAML script in a way that causes it to be interpreted as code. The update addresses the vulnerability by restricting XAML activities to a whitelisted set.
CVSS Score
8.8
EPSS Score
0.099
Published
2019-08-14
A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
CVSS Score
5.9
EPSS Score
0.092
Published
2019-05-16


Contact Us

Shodan ® - All rights reserved