CVE-2022-36872: Medium severity samsung pay vulnerability
Published Sep 9, 2022
·Updated
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
Affected Software
2 affected components
Samsung Samsung Pay Android<5.1.47
Samsung Samsung Pay Kr Android<5.0.63
Event History
Sep 9, 2022
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36872?
CVE-2022-36872 is classified as a high severity vulnerability due to its potential for unauthorized file access.
2
How can I fix CVE-2022-36872?
To fix CVE-2022-36872, update Samsung Pay to version 5.0.63 for KR or 5.1.47 for Global.
3
What type of vulnerability is CVE-2022-36872?
CVE-2022-36872 is a Pending Intent hijacking vulnerability that affects Samsung Pay.
4
Which versions of Samsung Pay are affected by CVE-2022-36872?
CVE-2022-36872 affects versions of Samsung Pay prior to 5.0.63 for KR and 5.1.47 for Global.
5
What can attackers achieve with CVE-2022-36872?
Attackers exploiting CVE-2022-36872 can access files without permission via implicit Intent.