Описание
Microsoft Dynamics GP Remote Code Execution Vulnerability
FAQ
How could an attacker exploit this vulnerability?
An authenticated user could send a specially crafted SQL request to a Dynamics GP Web Service and perform remote code execution.
According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of availability (A:H)? What does that mean for this vulnerability?
An attacker could impact availability of the data by assuming control of the server through remote code execution.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
8.8 High
CVSS3
Связанные уязвимости
Microsoft Dynamics GP Remote Code Execution Vulnerability
Microsoft Dynamics GP Remote Code Execution Vulnerability.
Уязвимость пакета программного обеспечения для бухгалтерского учета или планирования ресурсов предприятия среднего размера Microsoft Dynamics GP, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3