An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-12-23T21:10:36

Updated: 2021-12-23T21:10:36

Reserved: 2020-12-14T00:00:00


Link: CVE-2020-35398

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-12-23T22:15:07.333

Modified: 2021-12-29T19:03:58.050


Link: CVE-2020-35398

JSON object: View

cve-icon Redhat Information

No data.

CWE