Security Vulnerability fix for CVE-2018-8269? ('Microsoft.Data.OData' Denial of Service Vulnerability)

SOLVED

Sage 50 appears to be using an older version of microsoft.data.odata.dll in it's latest release (2022.2), which makes it vulnerable to a Denial of Service attack. 

Is there any plan for an upgrade to v5.8.4 or higher?

Location: c:\program files (x86)\sage 50 premium accounting version 2022\sageoverdrive\connectivityadapters\graphexcelapi\

Reference: msrc.microsoft.com/.../CVE-2018-8269

Parents
  • 0

    Hi Michael,

    Thanks for bringing this to our attention. Sage takes the security of our products seriously and as such, I have forwarded your feedback onto the Sage 50 Support team for review and follow-up. Will update you with any news.

    Warm Regards,
    Erzsi

Reply
  • 0

    Hi Michael,

    Thanks for bringing this to our attention. Sage takes the security of our products seriously and as such, I have forwarded your feedback onto the Sage 50 Support team for review and follow-up. Will update you with any news.

    Warm Regards,
    Erzsi

Children
No Data