The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-09-20T22:00:00Z
Updated: 2024-09-16T18:34:39.175Z
Reserved: 2017-09-20T00:00:00Z
Link: CVE-2015-9232
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-09-20T22:29:00.197
Modified: 2024-11-21T02:40:06.650
Link: CVE-2015-9232
Redhat
No data.