| [Japanese] | 
| JVNDB-2016-000161 | 
| Money Forward Apps for Android vulnerability that allows unintended operations | 
|
| 
 
Money Forward Apps for Android contain a vulnerability where unintended operations may be performed.
 Kenta Suefusa, Akinori Konishi and Tomonori Shiomi of Sprout Inc. reported this vulnerability to IPA.
 JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 5.3 (Medium) [IPA Score]
 
    Attack Vector: LocalAttack Complexity: LowPrivileges Required: NoneUser Interaction: RequiredScope: UnchangedConfidentiality Impact: LowIntegrity Impact: LowAvailability Impact: Low 
  CVSS V2 Severity:Base Metrics 5.1 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: HighAuthentication: NoneConfidentiality Impact: PartialIntegrity Impact: PartialAvailability Impact: Partial 
  
 | 
|
| 
 
	
 | 
| 
 
	SOURCENEXT CORPORATION
	
		Money Forward, Inc.Money Forward for AppPass (prior to v7.18.3)Money Forward for Chou Houdai (prior to v7.18.3)Money Forward for au SMARTPASS (prior to v7.18.0) 
		Money Forward (prior to v7.18.0) (Android App)Money Forward for YMFG (prior to v1.5.0) (Android App)Money Forward for The Gunma Bank (prior to v1.2.0) (Android App)Money Forward for SHIGA BANK (prior to v1.2.0) (Android App)Money Forward for SBI Sumishin Net Bank (prior to v1.6.0) (Android App)Money Forward for SHIZUOKA BANK (prior to v1.4.0) (Android App)Money Forward for Tokai Tokyo Securities (prior to v1.4.0) (Android App)Money Forward for THE TOHO BANK (prior to v1.3.0) (Android App) | 
| 
 
	
 | 
|
| 
 
When a user executes a malicious application, it may perform an unintended operation.
 | 
|
| 
 
[Update the Application]Update to the latest version according to the information provided by the developer.
 | 
|
| 
 
	SOURCENEXT CORPORATION
	
	Money Forward, Inc.
	
 | 
|
| 
 
	No Mapping(CWE-Other) [IPA Evaluation] | 
|
| 
 
	CVE-2016-4838  | 
|
| 
 
	JVN : JVN#49343562 National Vulnerability Database (NVD) : CVE-2016-4838  | 
|
| 
 
	[2016/09/20]Web page was published
 [2017/11/27]
 References : Content was added
 
 |