2023-11-07 21:03:21 +00:00

104 lines
3.3 KiB
JSON

{
"id": "CVE-2018-15661",
"sourceIdentifier": "cve@mitre.org",
"published": "2018-08-21T17:29:00.343",
"lastModified": "2023-11-07T02:53:18.297",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with accessibility permissions and the ability to read SMS messages, then the Forgot Password screen can be used to bypass authentication. NOTE: the vendor does not agree that this is a security issue requiring a fix"
},
{
"lang": "es",
"value": "** EN DISPUTA ** Se ha descubierto un problema en la aplicaci\u00f3n Ola Money (tambi\u00e9n conocida como com.olacabs.olamoney) 1.9.0 para Android. Si un atacante controla una aplicaci\u00f3n con permisos de accesibilidad y puede leer mensajes SMS, entonces la pantalla Forgot Password se puede usar para omitir la autenticaci\u00f3n. NOTA: el fabricante no est\u00e1 de acuerdo con que sea un fallo de seguridad que necesite una soluci\u00f3n."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.6,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "HIGH",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.6
},
"baseSeverity": "LOW",
"exploitabilityScore": 4.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:olacabs:ola_money:1.9.0:*:*:*:*:android:*:*",
"matchCriteriaId": "CF0E1D6F-A063-4B52-AAD2-94E9F88198EF"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/magicj3lly/appexploits/blob/master/OLA%20Money.pdf",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}