0% found this document useful (0 votes)
83 views2 pages

Mobile App Vulnerability Assessment

Uploaded by

Henock Getachew
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
83 views2 pages

Mobile App Vulnerability Assessment

Uploaded by

Henock Getachew
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Quixxi - Free Mobile App Vulnerability Scanner for Android... [Link]

com/#/

Docs ([Link]

Support ([Link]
([Link]

CBE Mobile Banking 5.0.2 [Link]

49 14 12 Nov 2023 04:19 PM GMT

8 4 2

Data Storage and Privacy 4 5

Cryptography 5 1

Network Communication 4 2

Platform Interactions 8 3

Code Quality and Build Settings 3 2

Resilience Requirements 3 1

Unsafe �les deletion High Fail CWE-200 ([Link] CVE-2018-3987 ([Link] View Details

Read/Write access to External Storage High Fail CWE-276 ([Link] CVE-2018-6599 ([Link] View Details

Cleartext Storage of Sensitive Information in app source code High Fail CWE-312 ([Link] CVE-2018-19981 ([Link] View Details

FIXABLE BY
Missing protection against screenshots & screensharing Medium Fail CWE-200 ([Link] CVE-2015-6630 ([Link] View Details

FIXABLE BY
No blurring for the app in background Medium Fail CWE-200 ([Link] CVE-2015-6630 ([Link] View Details
V2 Data Storage and Privacy ([Link]

Hidden elements in the user view High Pass CWE-919 ([Link] CVE-2019-2216 ([Link] View Details

Medium Pass CWE-530 ([Link] ,


ADB Backup allowed CVE-2017-16835 ([Link] View Details
CWE-312 ([Link]

Missing copy&paste protection from EditText �elds Medium Pass CWE-200 ([Link] CVE-2018-12481 ([Link] View Details

Low Pass CWE-477 ([Link] ,


Unsafe and deprecated �les con�guration CVE-2018-11544 ([Link] View Details
CWE-312 ([Link]

Weak Random Number Generator Medium Fail CWE-1241 ([Link] Multiple vulnerabilities ([Link] View Details

Weak Java Hash Code implementation Warning Fail CWE-327 ([Link] View Details

High Pass CVE-2019-8919 ([Link] ,


Cryptography: Predictable Initialization Vector CWE-329 ([Link] View Details
CVE-2018-18979 ([Link]

Medium Pass CAPEC-97 ([Link] ,


Unsecure cryptographic protocols CWE-327 ([Link] View Details
CVE-2017-15326 ([Link]
V3 Cryptography ([Link]
Medium Pass CVE-2018-14992 ([Link] ,
Weak Hashing Algorithms CWE-326 ([Link] View Details
CVE-2017-15999 ([Link]

Medium Pass CWE-798 ([Link] , CAPEC-97 ([Link] ,


Missing SQLite PRAGMA key protection View Details
CWE-321 ([Link] CVE-2018-15753 ([Link]

Strings Security based on Base64 Encoding Low Pass CWE-312 ([Link] .html) CAPEC-37 ([Link] View Details

Warning Pass CVE-2017-13107 ([Link] ,


Hardcoded SQLCipher Key CWE-798 ([Link] View Details
CVE-2017-13108 ([Link]

Unsafe TrustManager implementation High Fail CWE-295 ([Link] CVE-2020-5523 ([Link] View Details

Application uses HTTPURLConnection Low Fail View Details

Clear text tra�c is allowed in application High Pass CWE-319 ([Link] View Details
V5 Network Communication ([Link]
Deprecated implementation of SSL Sockets High Pass CWE-310 ([Link] CVE-2014-0224 ([Link] View Details

Unsafe HttpHost scheme for implementing https connections High Pass CWE-200 ([Link] CVE-2017-9491 ([Link] View Details

High Pass CWE-295 ([Link] , CVE-2017-9968 ([Link] ,


Missing Certi�cate Pinning View Details
CWE-254 ([Link] CVE-2018-20200 ([Link]

Improper Export of your Android Activities High Fail CWE-926 ([Link] CVE-2017-12816 ([Link] View Details

Improper Export of your Android Services High Fail CWE-926 ([Link] CAPEC-501 ([Link] View Details

High Fail CVE-2019-5454 ([Link] ,


Raw SQL queries used for SQLLite database CWE-89 ([Link] View Details
CVE-2020-0060 ([Link]

High Pass CWE-927 ([Link] , CAPEC-499 ([Link] ,


Improper Export of your Android Broadcast Receiver View Details
CWE-925 ([Link] CAPEC-501 ([Link]

Improper Export of your Android Content Providers High Pass CWE-926 ([Link] CVE-2018-14066 ([Link] View Details

CVE-2018-15004 ([Link] ,
WebView loads �les from external storage High Pass CWE-919 ([Link] CVE-2018-15002 ([Link] , View Details
CVE-2018-14995 ([Link]
V6 Platform Interactions ([Link]
Downloading Files using Android Download Manager High Pass CWE-200 ([Link] CVE-2016-6710 ([Link] View Details

High Pass CVE-2020-9548 ([Link] ,


Unsafe Jackson deserialization con�guration CWE-502 ([Link] View Details
CVE-2020-5411 ([Link]

Fragment Injection High Pass CWE-20 ([Link] CVE-2015-1261 ([Link] View Details

CVE-2019-9467 ([Link] ,
CVE-2019-9254 ([Link] ,
Medium Pass CWE-77 ([Link] ,
Command injection Vulnerability CVE-2019-15429 ([Link] , View Details
CWE-78 ([Link]
CAPEC-248 ([Link] ,
CAPEC-500 ([Link]

CVE-2019-2200 ([Link] ,
Low Pass CWE-926 ([Link] ,
Unsafe protection level for custom permissions CVE-2017-0593 ([Link] , View Details
CWE-732 ([Link]
CVE-2017-12816 ([Link]

Medium Fail CAPEC-133 ([Link] , FIXABLE BY


Debugging Information Provision CWE-215 ([Link] View Details
CVE-2018-6599 ([Link]

FIXABLE BY
Missing check for the download source Low Fail CWE-610 ([Link] CVE-2018-9582 ([Link] View Details

IP Address Disclosure Warning Fail CWE-200 ([Link] CVE-2018-9489 ([Link] View Details

CVE-2019-16273 ([Link] ,
V7 Code Quality and Build Settings ([Link] CVE-2019-16272 ([Link] ,
Debuggable App Medium Pass CWE-215 ([Link] View Details
CVE-2019-16241 ([Link] ,
CVE-2017-3750 ([Link]

CVE-2019-5961 ([Link] ,
Improper implementation of SslErrorHandler class Medium Pass CWE-703 ([Link] CVE-2019-14516 ([Link] , View Details
CVE-2019-11554 ([Link]

Native binaries contains debugging symbols Low Pass View Details

App seeks Root/Super user privileges High Fail CWE-250 ([Link] CVE-2019-16273 ([Link] View Details

Missing Native [C, C++] Code Medium Pass CAPEC-190 ([Link] View Details
V8 Resilience Requirements ([Link]
App allowed to run in a rooted device Low Pass CVE-2017-4896 ([Link] View Details

App allowed to run in an emulator Low Pass View Details

CWE ([Link] – Common Weakness Enumeration CVE ([Link] – Common Vulnerabilities and Exposures

MASVS ([Link] – Mobile Application Security Veri�cation Standard OWASP ([Link] – Open Web Application Security Project

Buy Full Report Sample Report ([Link]


10-24T00%3A00%3A00Z&se=2025-10-26T00%3A00%3A00Z&sp=rcw)

([Link]
Terms & Conditions ([Link] | Privacy Policy ([Link]

1 of 2 11/12/23, 19:23
Quixxi - Free Mobile App Vulnerability Scanner for Android... [Link]

Docs ([Link]

Support ([Link]
([Link]

Tested by thousands of Apps

([Link]
Terms & Conditions ([Link] | Privacy Policy ([Link]

2 of 2 11/12/23, 19:23

You might also like