CVE-2020-4100 Information

Description

\HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically core components and additional dependencies are loaded natively at runtime; however dynamically loaded components are only loaded as they are specifically requested. While this can have a positive impact on performance or grant additional functionality (for example a non-invasive update feature) it can also open the application to loading unintended code if not implemented properly.\

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Reference

https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080800

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

4.4

Share on: