Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-1265

Опубликовано: 10 сент. 2019
Источник: msrc
EPSS Низкий

Описание

Microsoft Yammer Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when Microsoft Yammer App for Android fails to apply the correct Intune MAM Policy.

This could allow an attacker to perform functions that are restricted by Intune Policy.

The security update addresses the vulnerability by correcting the way the policy is applied to Yammer App.

FAQ

How do I get the update for Yammer for Android?

  1. Tap the Google Play icon on your home screen.
  2. Swipe in from the left edge of the screen.
  3. Tap My apps & games.
  4. Tap the Update box next to the Yammer app.

Is there a direct link on the web?

Yes: https://play.google.com/store/apps/details?id=com.yammer.v1&hl=en_US

What versions of the Yammer for Android App contain the fix for this vulnerability?

Yammer for Android App versions 5.6.10 or higher are not affected by this vulnerability.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 89%
0.05034
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

A security feature bypass vulnerability exists when Microsoft Yammer App for Android fails to apply the correct Intune MAM Policy.This could allow an attacker to perform functions that are restricted by Intune Policy.The security update addresses the vulnerability by correcting the way the policy is applied to Yammer App., aka 'Microsoft Yammer Security Feature Bypass Vulnerability'.

github
больше 3 лет назад

A security feature bypass vulnerability exists when Microsoft Yammer App for Android fails to apply the correct Intune MAM Policy.This could allow an attacker to perform functions that are restricted by Intune Policy.The security update addresses the vulnerability by correcting the way the policy is applied to Yammer App., aka 'Microsoft Yammer Security Feature Bypass Vulnerability'.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость механизма реализации политики Intune MAM Policy программного средства для внутрикорпоративной связи и совместной работы Yammer for Android, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 89%
0.05034
Низкий