CVE-2024-37403

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ivanti:docs\@work:*:*:*:*:*:android:*:*

History

25 Mar 2025, 17:15

Type Values Removed Values Added
CWE CWE-24

Information

Published : 2024-08-07 04:17

Updated : 2025-03-25 17:15


NVD link : CVE-2024-37403

Mitre link : CVE-2024-37403

CVE.ORG link : CVE-2024-37403


JSON object : View

Products Affected

ivanti

  • docs\@work
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-24

Path Traversal: '../filedir'