Vulnerability Description
The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for SHIGA BANK (prior to v1.2.0), Money Forward for SHIZUOKA BANK (prior to v1.4.0), Money Forward for SBI Sumishin Net Bank (prior to v1.6.0), Money Forward for Tokai Tokyo Securities (prior to v1.4.0), Money Forward for THE TOHO BANK (prior to v1.3.0), Money Forward for YMFG (prior to v1.5.0) provided by Money Forward, Inc. and Money Forward for AppPass (prior to v7.18.3), Money Forward for au SMARTPASS (prior to v7.18.0), Money Forward for Chou Houdai (prior to v7.18.3) provided by SOURCENEXT CORPORATION do not properly implement the WebView class, which allows an attacker to disclose information stored on the device via a specially crafted application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moneyforward | Money Forward For Apppass | < 7.18.3 |
| Moneyforward | Money Forward For Au Smartpass | < 7.18.0 |
| Moneyforward | Money Forward For Chou Houdai | < 7.18.3 |
| Moneyforward | Money Forward For Sbi Sumishin Net Bank | < 1.6.0 |
| Moneyforward | Money Forward For Shiga Bank | < 1.2.0 |
| Moneyforward | Money Forward For Shizuoka Bank | < 1.4.0 |
| Moneyforward | Money Forward For The Gunma Bank | < 1.2.0 |
| Moneyforward | Money Forward For The Toho Bank | < 1.3.0 |
| Moneyforward | Money Forward For Tokai Tokyo Securities | < 1.4.0 |
| Moneyforward | Money Forward For Ymfg | < 1.5.0 |
Related Weaknesses (CWE)
References
- http://corp.moneyforward.com/info/20160920-mf-android/Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/93035Third Party AdvisoryVDB Entry
- http://www.sourcenext.com/support/i/160725_1Third Party AdvisoryVDB Entry
- https://jvn.jp/en/jp/JVN61297210/index.htmlThird Party AdvisoryVDB Entry
- http://corp.moneyforward.com/info/20160920-mf-android/Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/93035Third Party AdvisoryVDB Entry
- http://www.sourcenext.com/support/i/160725_1Third Party AdvisoryVDB Entry
- https://jvn.jp/en/jp/JVN61297210/index.htmlThird Party AdvisoryVDB Entry
FAQ
What is CVE-2016-4839?
CVE-2016-4839 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for SHIGA BANK (prior to v1.2.0), Money Forward for SHIZUOKA BANK (prior to v1.4.0)...
How severe is CVE-2016-4839?
CVE-2016-4839 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4839?
Check the references section above for vendor advisories and patch information. Affected products include: Moneyforward Money Forward For Apppass, Moneyforward Money Forward For Au Smartpass, Moneyforward Money Forward For Chou Houdai, Moneyforward Money Forward For Sbi Sumishin Net Bank, Moneyforward Money Forward For Shiga Bank.