CVE-2015-9232
Last modified
CVE-2015-9232 is a vulnerability of currently unknown severity. The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Good | Good For Enterprise | 3.0.0.415 |
References
- http://www.securityfocus.com/archive/1/536543Exploit, Mitigation, Third Party Advisory, VDB Entry
- https://www.modzero.ch/advisories/MZ-15-03-GOOD-Auth-Delegation.txtExploit, Mitigation, Third Party Advisory
- http://www.securityfocus.com/archive/1/536543Exploit, Mitigation, Third Party Advisory, VDB Entry
- https://www.modzero.ch/advisories/MZ-15-03-GOOD-Auth-Delegation.txtExploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-9232?
How severe is CVE-2015-9232?
How do I fix CVE-2015-9232?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-9226Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 a…
- CVE-2015-9227PHP remote file inclusion vulnerability in the get_file func…
- CVE-2015-9228In post-new.php in the Photocrati NextGEN Gallery plugin 2.1…
- CVE-2015-9229In the nggallery-manage-gallery page in the Photocrati NextG…4.8
- CVE-2015-9230In the admin/db-backup-security/db-backup-security.php page …4.8
- CVE-2015-9231iTerm2 3.x before 3.1.1 allows remote attackers to discover …
- CVE-2015-9233The cp-contact-form-with-paypal (aka CP Contact Form with Pa…8.8
- CVE-2015-9234The cp-contact-form-with-paypal (aka CP Contact Form with Pa…
- CVE-2015-9235In jsonwebtoken node module before 4.2.2 it is possible for …
- CVE-2015-9236Hapi versions less than 11.0.0 implement CORS incorrectly an…
- CVE-2015-9238secure-compare 3.0.0 and below do not actually compare two s…
- CVE-2015-9239ansi2html is vulnerable to regular expression denial of serv…7.5
Are you affected by CVE-2015-9232?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
