Microsoft Dynamics 365 vulnerabilities

87 known vulnerabilities affecting microsoft/dynamics_365.

Total CVEs
87
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH23MEDIUM61LOW2

Vulnerabilities

Page 5 of 5
CVE-2019-1229HIGHCVSS 8.8v9.02019-08-14
CVE-2019-1229 [HIGH] CVE-2019-1229: An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successful An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer privilege within Dynamics to gain control of the Web Role hosting the Dynamics installation. To exploit this vulnerability, an attacker needs to have credentials for a user that has permission to author c
nvd
CVE-2019-1008MEDIUMCVSS 5.9v8.2v9.02019-05-16
CVE-2019-1008 [MEDIUM] CVE-2019-1008: A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Pr A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
nvd
CVE-2018-8609HIGHCVSS 8.8≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8609 [HIGH] CWE-116 CVE-2018-8609: A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This affects Microsoft Dynamics 365.
nvd
CVE-2018-8606MEDIUMCVSS 5.4≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8606 [MEDIUM] CVE-2018-8606: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-20
nvd
CVE-2018-8605MEDIUMCVSS 5.4≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8605 [MEDIUM] CWE-79 CVE-2018-8605: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8606,
nvd
CVE-2018-8607MEDIUMCVSS 5.4≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8607 [MEDIUM] CVE-2018-8607: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-20
nvd
CVE-2018-8608MEDIUMCVSS 5.4≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8608 [MEDIUM] CVE-2018-8608: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-20
nvd