VYPR

Business Central

by Red Hat

CVEs (3)

  • CVE-2022-2458HigAug 10, 2022
    risk 0.53cvss 8.2epss 0.01

    XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software…

  • CVE-2019-14839HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.

  • CVE-2019-14886MedMar 5, 2020
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could…