CVE-2010-4214

The Wells Fargo Mobile application 1.1 for Android stores a username and password, along with account balances, in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:wellsfargo:wells_fargo_mobile:1.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:20

Type Values Removed Values Added
References () http://news.cnet.com/8301-27080_3-20021874-245.html - () http://news.cnet.com/8301-27080_3-20021874-245.html -
References () http://online.wsj.com/article/SB10001424052748703805704575594581203248658.html - () http://online.wsj.com/article/SB10001424052748703805704575594581203248658.html -
References () http://viaforensics.com/appwatchdog/wells-fargo-android.html - () http://viaforensics.com/appwatchdog/wells-fargo-android.html -

Information

Published : 2010-11-09 01:00

Updated : 2024-11-21 01:20


NVD link : CVE-2010-4214

Mitre link : CVE-2010-4214

CVE.ORG link : CVE-2010-4214


JSON object : View

Products Affected

wellsfargo

  • wells_fargo_mobile

google

  • android
CWE
CWE-310

Cryptographic Issues