Scan "Ascan"

Application summary

Platform: android

Package: com.ramco.ramcoerp

Version: 1.0.0.45

SHA1 Hash: 3a70137ddc6d0b32caf34abec01def7fd7125d22

Size: 20 MB

Scan summary

Icon

Date: May 15, 2019, 5:31 p.m.

Vulnerability risk dashboard
Code coverage (% methods)

10000/18798 methods

Risk Title Short description
Medium Insecure whitelist configuration Insecure whitelist configuration authorising access to all ressources.
Medium Application code not obfuscated Application's source code is not obfuscated and could be decompiled to retrieve the initial source code
Low Insecure Network Configuration Settings The application does not specify a network security configuration or sets insecure settings
Potentially Use non-random initialization vector (IV) The client uses a non random hardcoded initialization vector.
Potentially Intent Spoofing The application is vulnerable to intent spoofing which may lead to inappropriate access
Potentially Cryptographic Vulnerability: Hardcoded key The client supports combinations of cipher suites that suffer from known cryptographic weaknesses.
Potentially Cryptographic Vulnerability: Insecure Algorithm The client supports combinations of cipher suites that suffer from known cryptographic weaknesses.
Important Exported activites, services and broadcast receivers list List of all exported components (activities, services, broadcast receivers, content providers)
Info Call to Socket API List of Server Socket API calls
Info Application checks rooted device Presence of strings and methods indicating potential check for rooted device
Info Call to dangerous WebView settings API List of WebView API calls
Info Call to External Storage API List of external storage API calls
Info Call to Inter-Process-Communication (IPC) API List of Interp-Process Communication (IPC) calls
Info APK attack surface List of components potentially accepting user input
Info Call to logging API List of logging API calls
Info Apache Cordova Framework detected Application is built using the Cordova Apache Framework
Info Application components list List application's components
Info Application certificate information Application signing certificate details
Info Call to dynamic code loading API List of dynamic code loading API calls
Info Call to Reflection API List of reflection API calls
Info Call to Random API List of random API calls
Info Call to Crypto API List of crypto API calls
Info Call to SQLite query API List of SQLite query API calls
Info Implementation of a WebViewClient List of WebViewClient implementation
Info Call to native methods List of native methods calls
Info Call to command execution API List of all command execution API calls
Info List of JNI methods List of JNI methods defined in ELF files and used by the application
Info APK files list List of all files shipped in the application.
Info Android Manifest APK Manifest in XML
Info Obfuscated methods List of code obfuscation status of all application\s componenets