MEDIUM · 4.3

CVE-2014-5076

The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached bankin...

Vulnerability Description

The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LabanquepostaleLabanquepostale<= 3.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-5076?

CVE-2014-5076 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached bankin...

How severe is CVE-2014-5076?

CVE-2014-5076 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-5076?

Check the references section above for vendor advisories and patch information. Affected products include: Labanquepostale Labanquepostale.