4 results (0.010 seconds)

CVSS: 4.6EPSS: 0%CPEs: 1EXPL: 0

Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in the product via unspecified vectors. Android App "kintone mobile for Android" versiones 1.0.0 hasta 2.5, permite a un atacante obtener información de credenciales registrada en el producto por medio de vectores no especificados. • https://jvn.jp/en/jp/JVN78745667/index.html https://kb.cybozu.support/article/36211 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

The Cybozu kintone mobile for Android 1.0.6 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. Cybozu kintone mobile para Android 1.0.6 y versiones anteriores no verifica los certificados X.509 de servidores SSL, lo que permite a los atacantes man-in-the-middle falsificar servidores y obtener información confidencial a través de un certificado modificado. • http://www.securityfocus.com/bid/94547 https://jvn.jp/en/jp/JVN20252219/index.html https://support.cybozu.com/ja-jp/article/9719 • CWE-295: Improper Certificate Validation •

CVSS: 5.9EPSS: 0%CPEs: 6EXPL: 0

Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates. Kintone mobile para Android 1.0.0 hasta la versión 1.0.5 no verifica certificados SSL de servidor. • http://jvn.jp/en/jp/JVN91816422/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000056.html http://www.securityfocus.com/bid/97976 https://support.cybozu.com/ja-jp/article/9480 • CWE-295: Improper Certificate Validation •

CVSS: 2.6EPSS: 0%CPEs: 6EXPL: 0

The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application. La aplicación móvil Cybozu kintone 1.x en versiones anteriores a 1.0.6 para Android permite a atacantes descubrir un token de autenticación a través de una aplicación manipulada. • http://jvn.jp/en/jp/JVN89026267/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2016-000055 http://www.securityfocus.com/bid/96842 https://support.cybozu.com/ja-jp/article/9479 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •