PT-2017-8542 · Money Forward+1 · Money Forward For Tokai Tokyo Securities+10

Akinori Konishi

+2

·

Publicado

2017-05-12

·

Atualizado

2021-05-12

·

CVE-2016-4839

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Money Forward versions prior to 7.18.0 Money Forward for The Gunma Bank versions prior to 1.2.0 Money Forward for SHIGA BANK versions prior to 1.2.0 Money Forward for SHIZUOKA BANK versions prior to 1.4.0 Money Forward for SBI Sumishin Net Bank versions prior to 1.6.0 Money Forward for Tokai Tokyo Securities versions prior to 1.4.0 Money Forward for THE TOHO BANK versions prior to 1.3.0 Money Forward for YMFG versions prior to 1.5.0 Money Forward for AppPass versions prior to 7.18.3 Money Forward for au SMARTPASS versions prior to 7.18.0 Money Forward for Chou Houdai versions prior to 7.18.3
Description The Android apps do not properly implement the WebView class, allowing an attacker to disclose information stored on the device via a specially crafted application.
Recommendations For Money Forward versions prior to 7.18.0, update to version 7.18.0 or later. For Money Forward for The Gunma Bank versions prior to 1.2.0, update to version 1.2.0 or later. For Money Forward for SHIGA BANK versions prior to 1.2.0, update to version 1.2.0 or later. For Money Forward for SHIZUOKA BANK versions prior to 1.4.0, update to version 1.4.0 or later. For Money Forward for SBI Sumishin Net Bank versions prior to 1.6.0, update to version 1.6.0 or later. For Money Forward for Tokai Tokyo Securities versions prior to 1.4.0, update to version 1.4.0 or later. For Money Forward for THE TOHO BANK versions prior to 1.3.0, update to version 1.3.0 or later. For Money Forward for YMFG versions prior to 1.5.0, update to version 1.5.0 or later. For Money Forward for AppPass versions prior to 7.18.3, update to version 7.18.3 or later. For Money Forward for au SMARTPASS versions prior to 7.18.0, update to version 7.18.0 or later. For Money Forward for Chou Houdai versions prior to 7.18.3, update to version 7.18.3 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4839

Produtos afetados

Android
Money Forward
Money Forward For Apppass
Money Forward For Chou Houdai
Money Forward For Sbi Sumishin Net Bank
Money Forward For Shiga Bank
Money Forward For The Toho Bank
Money Forward For The Gunma Bank
Money Forward For Tokai Tokyo Securities
Money Forward For Ymfg
Money Forward For Au Smartpass