An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not reveal much sensitive information."
Metrics
Affected Vendors & Products
References
History
Mon, 15 Sep 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 allowing attackers to gain sensitive information without UPI PIN such as account information, balances, transaction history, and other unspecified information. | An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not reveal much sensitive information." |
Mon, 15 Sep 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Axis
Axis axis Mobile App Google android |
|
Vendors & Products |
Axis
Axis axis Mobile App Google android |
Fri, 12 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 allowing attackers to gain sensitive information without UPI PIN such as account information, balances, transaction history, and other unspecified information. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-09-12T00:00:00.000Z
Updated: 2025-09-15T17:30:03.071Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-56467

Updated: 2025-09-12T17:33:17.867Z

Status : Awaiting Analysis
Published: 2025-09-12T17:15:47.757
Modified: 2025-09-15T18:15:39.167
Link: CVE-2025-56467

No data.