CVE-2019-8350 - CVE House
Back to Database
Status published Medium CVE-2019-8350

The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed...

Vulnerability Description

The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password to the keyboard autocomplete functionality. Third-party Android keyboards that capture the password may store this password in cleartext, or transmit the password to third-party services for keyboard customization purposes. A compromise of any datastore that contains keyboard autocompletion caches would result in the disclosure of the user's Simple Bank password.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-8350

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

better banking
Vulnerable Versions:
2.45.0

Timeline

Official Publish: May 13th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AC:L/AV:P/A:H/C:H/I:H/PR:L/S:U/UI:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.