PT-2023-32690 · Emarsys · Emarsys Sdk For Android

Published

2022-02-01

·

Updated

2025-10-31

·

CVE-2023-6542

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Emarsys SDK for Android (affected versions not specified)
Description The issue is due to a lack of proper authorization checks in the Emarsys SDK for Android, allowing an attacker to call a particular activity and forward web pages and/or deep links without validation directly from the host application. On a successful attack, an attacker could navigate to an arbitrary URL, including application deep links on the device. This could potentially lead to sensitive data leaks from an app's private data directory and allow loading remote contents into an app overlay.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-05011
CVE-2023-6542

Affected Products

Emarsys Sdk For Android