CVE-2024-37403

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ivanti:docs\@work:*:*:*:*:*:android:*:*

History

12 Aug 2024, 18:55

Type Values Removed Values Added
CPE cpe:2.3:a:ivanti:docs\@work:*:*:*:*:*:android:*:*
First Time Ivanti
Ivanti docs\@work
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://forums.ivanti.com/s/article/Security-Advisory-CVE-2024-37403-Dirty-Stream-for-Ivanti-Docs-Work-for-Android - () https://forums.ivanti.com/s/article/Security-Advisory-CVE-2024-37403-Dirty-Stream-for-Ivanti-Docs-Work-for-Android - Vendor Advisory

07 Aug 2024, 04:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-07 04:17

Updated : 2025-03-25 17:15


NVD link : CVE-2024-37403

Mitre link : CVE-2024-37403


JSON object : View

Products Affected

ivanti

  • docs\@work
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')