CVE Vulnerabilities

CVE-2022-36871

Published: Sep 09, 2022 | Modified: Oct 01, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

Affected Software

Name Vendor Start Version End Version
Samsung_pay Samsung * 5.1.47 (excluding)
Samsung_pay_kr Samsung * 5.0.63 (excluding)

References