← Back

CVE-2020-4100

nvd nist
Published: Jul 15, 2020Modified: Nov 21, 2024

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Exploitability: 0.8 / Impact: 3.6
Source: NVD

Description

"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtime; however, dynamically loaded components are only loaded as they are specifically requested. While this can have a positive impact on performance, or grant additional functionality (for example, a non-invasive update feature), it can also open the application to loading unintended code if not implemented properly."

Affected (1)

Products: Hcltechsw: Hcl Verse
1 product
Hcl Verse
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0.4

References (2)

Timeline

No history available yet.