CVE Feed

    Dashboard / CVE / CVE-2015-9232

    CVE-2015-9232

    The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.

    Published:Sep 20, 2017
    Last Modified:Apr 20, 2025
    EPS:Sep 20, 2017
    EPSS Score:0.00136
    CVSS Score:5.3

    Affected Products

    Vendor
    Good
    Product
    Good For Enterprise

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High