Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code (βCode Injectionβ) by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.
https://support.citrix.com/article/CTX286763
https://support.citrix.com/article/CTX286763
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8274