Medium severity5.3NVD Advisory· Published Dec 23, 2021· Updated Jun 17, 2026
CVE-2020-35398
CVE-2020-35398
Description
An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:utimf:uti_mutual_fund_invest_online:*:*:*:*:*:android:*:*Range: <=5.4.28
- UTI Mutual fund/UTI Mutual fund Android applicationdescription
- Range: <=5.4.18
Patches
Vulnerability mechanics
References
2- cvewalkthrough.com/cve-2020-35398-uti-mutual-fund-android-application-username-enumeration/nvdExploitThird Party Advisory
- play.google.com/store/apps/detailsnvdProductThird Party Advisory
News mentions
0No linked articles in our index yet.