Microsoft Dynamics AX Enterprise Portal XSS Vulnerability
RISK: Medium Risk
TYPE: Servers - Internet App Servers
A cross-site scripting vulnerability exists in Microsoft Dynamics AX Enterprise Portal that could result in information disclosure or elevation of privilege if a user clicks a specially crafted URL that contains malicious JavaScript elements. Because of the vulnerability, when the malicious JavaScript is echoed back to the user's browser, the resulting page could allow an attacker to issue Microsoft Dynamics AX Enterprise Portal commands in the context of the authenticated user on the targeted Microsoft Dynamics AX Enterprise Portal site.
Impact
- Elevation of Privilege
System / Technologies affected
- Microsoft Dynamics AX 2012
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/ms12-040
Vulnerability Identifier
Source
Related Link
Share with