CVE-2023-6542

Source
https://cve.org/CVERecord?id=CVE-2023-6542
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6542.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-6542
Published
2023-12-12T01:36:22.773Z
Modified
2026-08-12T03:51:34.294216607Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Improper Export of Android Application Components in SAP EMARSYS SDK ANDROID
Details

Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to arbitrary URL including application deep links on the device.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6542.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "100"
                },
                {
                    "last_affected": "100"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "sap"
}
References

Affected packages

Git / github.com/emartech/android-emarsys-sdk

Affected ranges

Type
GIT
Repo
https://github.com/emartech/android-emarsys-sdk
Events
Database specific
Show details
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:sap:emarsys_sdk:3.6.2:*:*:*:*:android:*:*",
    "extracted_events": [
        {
            "introduced": "3.6.2"
        },
        {
            "last_affected": "3.6.2"
        }
    ]
}

Affected versions

3.*
3.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6542.json"