Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:LSamsung Galaxy Watch Plugin
APPSamsung< 2.2.11.22081151
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2022-36873MEDIUM5.9same product
Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2...
CVE-2022-36874MEDIUM5.9same product
Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040...
CVE-2021-25420MEDIUM5.5same product
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker ...
CVE-2022-25823LOW1.9same product
Luka Information Exposure w Galaxy Watch Plugin przed wersją 2.2.05.220126741 umożliwia atakującym dostęp do i...
CVE-2022-25827LOW1.9same product
Luka Information Exposure w Galaxy Watch Plugin w wersji przed 2.2.05.22012751 umożliwia atakującemu dostęp do...