CVE-2010-2011 Information

Description

Microsoft Dynamics GP uses a substitution cipher to encrypt the system password field and unspecified other fields which makes it easier for remote authenticated users to obtain sensitive information by decrypting a field’s contents.

Reference

http://blogs.msdn.com/developingfordynamicsgp/archive/2008/10/02/why-does-microsoft-dynamics-gp-encrypt-passwords.aspx http://slashdot.org/story/10/05/21/1437227 http://www.christopherkois.com/?p=448

Share on: