Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=09 | Vendor Advisory |
https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=09 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:13
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.0 |
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=09 - Vendor Advisory |
16 Sep 2022, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Sep 2022, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Sep 2022, 15:29
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://security.samsungmobile.com/serviceWeb.smsb?year==2022&month=09 - Vendor Advisory | |
CPE | cpe:2.3:a:samsung:samsung_pay_kr:*:*:*:*:*:android:*:* cpe:2.3:a:samsung:samsung_pay:*:*:*:*:*:android:*:* |
|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
09 Sep 2022, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-09-09 15:15
Updated : 2024-11-21 07:13
NVD link : CVE-2022-36870
Mitre link : CVE-2022-36870
CVE.ORG link : CVE-2022-36870
JSON object : View
Products Affected
samsung
- samsung_pay_kr
- samsung_pay
CWE