CVE-2018-17108: Sbi Buddy

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeover attacks by intercepting a security-question response during the initial configuration of the application.

Affected products

  • Sbi Sbi Buddy: version 1.41 only; version 1.42 only

Published 2018-09-16. Last modified 2026-06-17.