CVE-2024-21380

Summary

Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft Dynamics 365 Business Central 2022 Release Wave 221.0.0 < 21.0.63175affected
MicrosoftMicrosoft Dynamics 365 Business Central 2023 Release Wave 122.0.0 < 22.0.63124affected
MicrosoftMicrosoft Dynamics 365 Business Central 2023 Release Wave 223.0.0 < 23.0.15712affected

Weaknesses

  • CWE-200: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References