CVE-2017-4896
low
CVSS v3
3.8
CVSS v2
2.1
VIR risk
3.8
Description
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.
Predictions
Exploit likelihood
38%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@vmware.com — http://www.vmware.com/us/security/advisories/VMSA-2017-0001.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| vmware | airwatch_agent | - | |
| vmware | airwatch_inbox | - | |
References
Verify integrity in audit chain (admin only). AS-IS.