PatchSiren

Utarit Information Technologies CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Utarit Information Technologies CVE published 2024-02-15

CVE-2023-6255

CVE-2023-6255 is a high-severity hard-coded credentials issue in Utarit SoliPay Mobile App affecting versions before 5.0.8. The published NVD record maps the issue to a confidentiality-only attack path, and the available advisory material indicates sensitive strings may be readable within the executable. Because the flaw can be reached without privileges or user interaction, organizations should prioritiz [truncated]

CRITICAL Utarit Information Technologies CVE published 2024-02-15

CVE-2023-5155

CVE-2023-5155 is a critical SQL injection vulnerability in Utarit SoliPay Mobile App affecting versions before 5.0.8. NVD assigns it CVSS 9.8 with network access, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. Organizations using affected versions should prioritize upgrading to 5.0.8 or later and confirm that no vulnerable installations remain.

HIGH Utarit Information Technologies CVE published 2024-02-15

CVE-2023-4993

CVE-2023-4993 is a high-severity vulnerability in Utarit Information Technologies’ SoliPay Mobile App affecting versions before 5.0.8. The published NVD vector indicates network-based exploitation with no privileges or user interaction required and confidentiality impact only, so remediation should focus on quickly removing vulnerable app versions from use.