CVE Database
/

CVE-2020-16943

Back to search

CVE-2020-16943

Published: Oct 16, 2020

Modified: Nov 15, 2024

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

<p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker would need to send a specially crafted request to an affected server.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Dynamics 365 Commerce performs authorization checks.</p>

VendorProductVersions

Microsoft

Dynamics 365 Commerce version 10.0.12

affected
10.0.0 - < publication

Microsoft

Dynamics 365 Commerce version 10.0.13

affected
10.0.0 - < publication

Microsoft

Dynamics 365 Commerce version 10.0.14

affected
10.0.0 - < publication

Microsoft

Dynamics 365 Commerce version 10.0.15

affected
10.0.0 - < publication

Microsoft

Dynamics 365 Commerce version 10.0.16

affected
10.0.0 - < publication

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now