The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.
Conclusion & alert: CVE-2015-9232 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.14%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-17 | 0.23% | 0.14% | -0.08% |
| 2 | 2024-09-17 | 0.61% | 0.23% | -0.38% |
| 3 | 2024-03-15 | — | 0.61% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.0 | MEDIUM |
|
1.6 | 3.6 | [email protected] |
| 2.6 | 2.0 | LOW |
|
4.9 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| good | good_for_enterprise | 3.0.0.415 | cpe:2.3:a:good:good_for_enterprise:3.0.0.415:*:*:*:*:android:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/archive/1/536543 | Exploit Mitigation Third Party Advisory VDB Entry |
| https://community.blackberry.com/community/blogs/blog/2015/10/02/what-you-need-to-know-modzero-insecure-application-coupling | Third Party Advisory |
| https://www.modzero.ch/advisories/MZ-15-03-GOOD-Auth-Delegation.txt | Exploit Mitigation Third Party Advisory |