CVE-2014-0261

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
15/01/2014
Last modified:
11/04/2025

Description

Microsoft Dynamics AX 4.0 SP2, 2009 SP1, 2012, and 2012 R2 allows remote authenticated users to cause a denial of service (instance outage) via crafted data to an Application Object Server (AOS) instance, aka "Query Filter DoS Vulnerability."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:dynamics_ax:4.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:dynamics_ax:2009:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:dynamics_ax:2012:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:dynamics_ax:2012:r2:*:*:*:*:*:*