CVE-2019-2211: SQL Injection
Published Nov 4, 2019
·Updated
In createProjectionMapForQuery of TvProvider.java, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269669
Affected Software
5 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android
Event History
Nov 4, 2019
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 13, 2019
CVE Published
via MITRE·05:34 PM
Data Sourced
via MITRE·05:34 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are identified as affected?
Android 8.0, 8.1, 9, and 10 are listed as affected.
2
Does exploitation require user interaction or additional execution privileges?
No. The issue is described as requiring neither user interaction nor additional execution privileges.
3
What is the documented impact of successful exploitation?
Successful exploitation could result in local information disclosure. The supplied CVSS vector indicates high confidentiality impact with no integrity or availability impact.