Dynamic Code Loading Vulnerability in HCL Verse for Android
CVE-2020-4100
4.4MEDIUM
What is CVE-2020-4100?
The dynamic code loading mechanism in HCL Verse for Android allows certain components to be loaded conditionally rather than at startup. While this approach can enhance performance and support in-app updates, it introduces a potential risk if the code loading is not securely managed. If an attacker can manipulate the request for these dynamic components, they might execute unintended code, compromising the integrity and security of the application. Proper implementation and validation are essential to mitigate these risks and protect user data.
Affected Version(s)
"HCL Verse for Android" "May 2020 Release (11.0.4) of HCL Verse Mobile for Android and older versions"