Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Serious security flaws have been fixed in Microsoft Dynamics 365 and Power Apps Web API
Global Security

Serious security flaws have been fixed in Microsoft Dynamics 365 and Power Apps Web API

AdminBy AdminJanuary 2, 2025No Comments2 Mins Read
Microsoft Dynamics 365 and Power Apps Web API
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 2, 2025Ravi LakshmananVulnerability / Data Protection

Microsoft Dynamics 365 and Power Apps Web API

Details have emerged about three fixed security vulnerabilities in Dynamics 365 and Power Apps Web API that could lead to data disclosure.

Disadvantages revealed by Melbourne-based cyber security company Stratus Security, were eliminated as of May 2024. Two of the three weaknesses are in Power Platform OData Web API Filterand the third vulnerability is rooted in the FetchXML API.

The root cause of the first vulnerability is the lack of access control for the OData web API filter, which allows access to table of contacts that holds confidential information for example, full names, phone numbers, addresses, financial data, and password hashes.

Cyber ​​security

A threat actor could then use the flaw to perform a boolean search to extract the full hash, successively guessing each character of the hash until the correct value is determined.

“For example, we start by sending startswith(adx_identity_passwordhash, ‘a’), then startswith(adx_identity_passwordhash ‘aa’), then starts with (adx_identity_passwordhash , ‘ab’) and so on until it returns results that start with ab,” Stratus Security said.

“We continue this process until the query returns results that begin with ‘ab.’ Eventually, when no more characters return the correct result, we know we got the full value.”

Microsoft Dynamics 365 and Power Apps Web API

A second vulnerability, on the other hand, is using the orderby clause in the same API to retrieve data from a required database table column (eg Email address1which links to the primary email address for the contact).

Finally, Stratus Security has also discovered that the FetchXML API can be used in conjunction with the contact table to access restricted columns using an orderby query.

Cyber ​​security

“Using the FetchXML API, an attacker can create an orderby query for any column, completely bypassing existing access controls,” it said. “Unlike previous vulnerabilities, this method does not require orderby to be placed in descending order, which adds a level of flexibility to the attack.”

Therefore, an attacker exploiting these flaws could compile a list of password and email hashes and then crack the passwords or sell the data.

“The discovery of vulnerabilities in Dynamics 365 and the Power Apps API highlights an important reminder that cybersecurity requires constant vigilance, especially for large companies that store as much data as Microsoft,” Stratus Security said.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.