CVE-2020-35398
Summary
| CVE | CVE-2020-35398 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-23 22:15:00 UTC |
| Updated | 2021-12-29 19:03:00 UTC |
| Description | An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted. |
Risk And Classification
Problem Types: CWE-203
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Utimf | Uti Mutual Fund Invest Online | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| UTI Mutual Fund Invest in Mutual Fund Online – Apps on Google Play | MISC | play.google.com | |
| CVE-2020-35398: UTI Mutual fund Android Application- Username Enumeration – CVEWalkthrough | MISC | cvewalkthrough.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.