3.3
CVE-2020-16943
- EPSS 1.12%
- Veröffentlicht 16.10.2020 23:15:15
- Zuletzt bearbeitet 23.02.2026 18:21:29
- Erkennungen
Dynamics 365 Commerce Elevation of Privilege Vulnerability
<p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker would need to send a specially crafted request to an affected server.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Dynamics 365 Commerce performs authorization checks.</p>
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Dynamics 365 Version - SwEdition commerce
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.12% | 0.623 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.3 | 6.5 | 2.9 |
AV:A/AC:L/Au:N/C:N/I:P/A:N
|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| Microsoft | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16943