CVE-2015-9232
Last modified
CVE-2015-9232 is a vulnerability of currently unknown severity. The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Good | Good For Enterprise | 3.0.0.415 |
References
- http://www.securityfocus.com/archive/1/536543Exploit, Mitigation, Third Party Advisory, VDB Entry
- https://www.modzero.ch/advisories/MZ-15-03-GOOD-Auth-Delegation.txtExploit, Mitigation, Third Party Advisory
- http://www.securityfocus.com/archive/1/536543Exploit, Mitigation, Third Party Advisory, VDB Entry
- https://www.modzero.ch/advisories/MZ-15-03-GOOD-Auth-Delegation.txtExploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-9232?
How severe is CVE-2015-9232?
How do I fix CVE-2015-9232?
Are you affected by CVE-2015-9232?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
