Vulnerability Name: | CVE-2012-6636 (CCN-176942) | ||||||||||||||||
Assigned: | 2014-02-07 | ||||||||||||||||
Published: | 2014-02-07 | ||||||||||||||||
Updated: | 2020-07-28 | ||||||||||||||||
Summary: | The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710. | ||||||||||||||||
CVSS v3 Severity: | 7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.2 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MISC Type: UNKNOWN http://50.56.33.56/blog/?p=314 Source: MITRE Type: CNA CVE-2012-6636 Source: CONFIRM Type: UNKNOWN http://developer.android.com/reference/android/os/Build.VERSION_CODES.html#JELLY_BEAN_MR1 Source: CONFIRM Type: UNKNOWN http://developer.android.com/reference/android/webkit/WebView.html#addJavascriptInterface%28java.lang.Object,%20java.lang.String%29 Source: JVN Type: UNKNOWN JVN#62161191 Source: MLIST Type: UNKNOWN [oss-security] 20140207 Re: CVE request: multiple issues in Apache Cordova/PhoneGap Source: MISC Type: Exploit http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf Source: MISC Type: UNKNOWN http://www.internetsociety.org/ndss2014/programme#session3 Source: CCN Type: Android Web site Google Android Source: XF Type: UNKNOWN android-cve20126636-code-exec(176942) Source: CONFIRM Type: UNKNOWN https://support.lenovo.com/us/en/product_security/len_6421 Source: CCN Type: oss-sec Mailing List, Fri, 7 Feb 2014 12:49:00 -0500 (EST) Re: CVE request: multiple issues in Apache Cordova/PhoneGap Source: CCN Type: Rapid7 Vulnerability and Exploit Database [05-30-2018] Android Browser and WebView addJavascriptInterface Code Execution | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |