An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not reveal much sensitive information."
Metrics
Affected Vendors & Products
References
History
Mon, 15 Sep 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 allowing attackers to gain sensitive information without UPI PIN such as account information, balances, transaction history, and other unspecified information. | An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not reveal much sensitive information." |
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axis
Axis axis Mobile App Google android |
|
| Vendors & Products |
Axis
Axis axis Mobile App Google android |
Fri, 12 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 allowing attackers to gain sensitive information without UPI PIN such as account information, balances, transaction history, and other unspecified information. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-09-12T00:00:00.000Z
Updated: 2025-09-15T17:30:03.071Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-56467
Updated: 2025-09-12T17:33:17.867Z
Status : Awaiting Analysis
Published: 2025-09-12T17:15:47.757
Modified: 2025-09-15T18:15:39.167
Link: CVE-2025-56467
No data.