CVE-2025-56467

An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not reveal much sensitive information."
Configurations

No configuration.

History

15 Sep 2025, 18:15

Type Values Removed Values Added
Summary (en) An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 allowing attackers to gain sensitive information without UPI PIN such as account information, balances, transaction history, and other unspecified information. (en) An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not reveal much sensitive information."

12 Sep 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-200
References
  • () https://github.com/dewcode91/security-research/blob/main/CVE-2025-56467.mdhttps://github.com/dewcode91/security-research/blob/main/CVE-2025-56467.md -

12 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-12 17:15

Updated : 2025-09-15 18:15


NVD link : CVE-2025-56467

Mitre link : CVE-2025-56467

CVE.ORG link : CVE-2025-56467


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor