CVE-2021-43388

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
14/12/2021
Last modified:
16/12/2021

Description

Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the manifest) is False.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unisys:cargo_mobile:*:*:*:*:*:*:*:* 1.2.29 (excluding)