CVE-2010-2011
Microsoft Dynamics GP - Sensitive Information Exposure via Substitution Cipher
Title source: llmDescription
Microsoft Dynamics GP uses a substitution cipher to encrypt the system password field and unspecified other fields, which makes it easier for remote authenticated users to obtain sensitive information by decrypting a field's contents.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
http://blogs.msdn.com/developingfordynamicsgp/archive/2008/10/02/why-does-microsoft-dynamics-gp-encrypt-passwords.aspx
Various Sources x_refsource_misc
http://www.christopherkois.com/?p=448
Various Sources x_refsource_misc
http://slashdot.org/story/10/05/21/1437227
Scores
EPSS
0.1074
EPSS Percentile
95.4%
Details
CWE
CWE-310
Status
published
Products (1)
microsoft/dynamics_gp
Published
May 21, 2010
Tracked Since
Feb 18, 2026