← Back

CVE-2020-35398

nvd nist
Published: Dec 23, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.

Affected (1)

1 product
Uti Mutual Fund Invest Online
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.4.28

Timeline

No history available yet.