CVE-2015-9232

UnknownEPSS 0.92%

Last modified

CVE-2015-9232 is a vulnerability of currently unknown severity. The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. EPSS estimates a 0.92% chance of exploitation in the next 30 days.

Description

The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.

Metrics

EPSS Probability
0.92%

55.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GoodGood For Enterprise3.0.0.415

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-9232?
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.
How severe is CVE-2015-9232?
Severity scoring for CVE-2015-9232 is pending analysis. The EPSS model estimates a 0.92% probability of exploitation in the next 30 days.
How do I fix CVE-2015-9232?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-9232?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST