{"api_version":"1","generated_at":"2026-07-23T12:31:14+00:00","cve":"CVE-2020-35398","urls":{"html":"https://cve.report/CVE-2020-35398","api":"https://cve.report/api/cve/CVE-2020-35398.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-35398","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-35398"},"summary":{"title":"CVE-2020-35398","description":"An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-12-23 22:15:00","updated_at":"2021-12-29 19:03:00"},"problem_types":["CWE-203"],"metrics":[],"references":[{"url":"https://play.google.com/store/apps/details?id=com.utimutualfunds.utimutualfund&hl=en_IN&gl=US","name":"https://play.google.com/store/apps/details?id=com.utimutualfunds.utimutualfund&hl=en_IN&gl=US","refsource":"MISC","tags":[],"title":"UTI Mutual Fund Invest in Mutual Fund Online – Apps on Google Play","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cvewalkthrough.com/cve-2020-35398-uti-mutual-fund-android-application-username-enumeration/","name":"https://cvewalkthrough.com/cve-2020-35398-uti-mutual-fund-android-application-username-enumeration/","refsource":"MISC","tags":[],"title":"CVE-2020-35398:  UTI Mutual fund Android Application- Username Enumeration – CVEWalkthrough","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-35398","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-35398","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"35398","vulnerable":"1","versionEndIncluding":"5.4.28","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"utimf","cpe5":"uti_mutual_fund_invest_online","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-35398","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://play.google.com/store/apps/details?id=com.utimutualfunds.utimutualfund&hl=en_IN&gl=US","refsource":"MISC","name":"https://play.google.com/store/apps/details?id=com.utimutualfunds.utimutualfund&hl=en_IN&gl=US"},{"refsource":"MISC","name":"https://cvewalkthrough.com/cve-2020-35398-uti-mutual-fund-android-application-username-enumeration/","url":"https://cvewalkthrough.com/cve-2020-35398-uti-mutual-fund-android-application-username-enumeration/"}]}},"nvd":{"publishedDate":"2021-12-23 22:15:00","lastModifiedDate":"2021-12-29 19:03:00","problem_types":["CWE-203"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:utimf:uti_mutual_fund_invest_online:*:*:*:*:*:android:*:*","versionEndIncluding":"5.4.28","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"35398","Ordinal":"193898","Title":"CVE-2020-35398","CVE":"CVE-2020-35398","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"35398","Ordinal":"1","NoteData":"An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"35398","Ordinal":"2","NoteData":"2021-12-23","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"35398","Ordinal":"3","NoteData":"2021-12-23","Type":"Other","Title":"Modified"}]}}}