漏洞信息详情
多款Money Forward和SOURCENEXT CORPORATION产品安全漏洞
- CNNVD编号:CNNVD-201609-545
- 危害等级: 高危
- CVE编号: CVE-2016-4838
- 漏洞类型: 输入验证错误
- 发布时间: 2016-09-22
- 威胁类型: 本地
- 更新时间: 2021-05-13
- 厂 商: money_forward_inc
- 漏洞来源: Akinori Konishi a...
漏洞简介
CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android Apps Money Forward和SOURCENEXT CORPORATION Money Forward for AppPass等都是资金管理软件。CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android Apps Money Forward是日本Money Forward公司的基于CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android系统的财富管理应用程序。SOURCENEXT CORPORATION Money Forward for AppPass是日本SOURCENEXT CORPORATION公司的财富管理应用程序。
多款Money Forward和SOURCENEXT CORPORATION产品中存在存在安全漏洞。攻击者可借助特制的应用程序利用该漏洞执行未授权的操作。以下产品和版本受到影响:CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android Apps Money Forward 7.18.0之前的版本;Money Forward for The Gunma Bank 1.2.0之前的版本;Money Forward for SHIGA BANK 1.2.0之前的版本;Money Forward for SHIZUOKA BANK 1.4.0之前的版本;Money Forward for SBI Sumishin Net Bank 1.6.0之前的版本;Money Forward for Tokai Tokyo Securities 1.4.0之前的版本;Money Forward for THE TOHO BANK 1.3.0之前的版本;Money Forward for YMFG 1.5.0之前的版本;SOURCENEXT CORPORATION Money Forward for AppPass 7.18.3之前的版本;SOURCENEXT CORPORATION Money Forward for au SMARTPASS 7.18.0之前的版本;SOURCENEXT CORPORATION Money Forward for Chou Houdai 7.18.3之前的版本。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
http://corp.moneyforward.com/info/20160920-mf-CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android/
参考网址
来源:MISC
链接:http://www.sourcenext.com/support/i/160725_1
来源:JVN
链接:https://jvn.jp/en/jp/JVN49343562/index.HTML
来源:CONFIRM
链接:http://corp.moneyforward.com/info/20160920-mf-CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android/
来源:BID
链接:https://www.securityfocus.com/bid/93034
受影响实体
- Money_forward_inc Money_forward_for_chou_houdai:-:~~~CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android~~
- Money_forward_inc Money_forward_for_au_smartpass:-:~~~CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android~~
- Money_forward_inc Money_forward_for_apppass:-:~~~CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android~~
- Money_forward_inc Money_forward_for_shizuoka_bank:-:~~~CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android~~
- Money_forward_inc Money_forward_for_shiga_bank:-:~~~CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android~~
补丁
- Money Forward Apps for CMS.zone.ci/e/tags/htag.php?tag=Android target=_blank class=infotextkey>Android 安全漏洞的修复措施
评论