Vulnerability Description
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Labanquepostale | Labanquepostale | <= 3.2 |
Related Weaknesses (CWE)
References
- https://www.youtube.com/watch?v=MF9lrh1kpDsExploit
- https://www.youtube.com/watch?v=MF9lrh1kpDsExploit
FAQ
What is CVE-2014-5076?
CVE-2014-5076 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached bankin...
How severe is CVE-2014-5076?
CVE-2014-5076 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-5076?
Check the references section above for vendor advisories and patch information. Affected products include: Labanquepostale Labanquepostale.