CVE-2019-5954
Summary
| CVE | CVE-2019-5954 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-17 16:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | JR East Japan train operation information push notification App for Android version 1.2.4 and earlier allows remote attackers to bypass access restriction to obtain or alter the user's registered information via unspecified vectors. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jreast | Jr East Japan | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.jreast.co.jp/press/2018/20190310.pdf | MISC | www.jreast.co.jp | Vendor Advisory |
| JVN#01119243: API server used by JR East Japan train operation information push notification App for Android fails to restrict access permissions | MISC | jvn.jp | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.