PT-2019-9955 · Amazon · Amazon Aws Sdk For Android

Published

2019-04-04

·

Updated

2021-05-10

·

CVE-2018-19981

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Amazon AWS SDK for Android versions <=2.8.5
Description The issue allows an attacker to access plain text AWS STS Temporary Credentials stored by the Amazon AWS SDK for Android using Android SharedPreferences. These credentials can be used to create authenticated and/or authorized requests. However, exploitation requires the attacker to have "root" privilege access to the Android filesystem, implying the device has been compromised.
Recommendations For Amazon AWS SDK for Android versions <=2.8.5, consider updating to a version greater than 2.8.5 to resolve the issue. As a temporary workaround, restrict access to the Android filesystem to minimize the risk of exploitation.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19981

Affected Products

Amazon Aws Sdk For Android