The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.