Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
References
Link | Resource |
---|---|
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04037en_us | Vendor Advisory |
Configurations
Information
Published : 2020-09-23 06:15
Updated : 2020-09-29 11:07
NVD link : CVE-2020-24626
Mitre link : CVE-2020-24626
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
hpe
- utility_computing_service_meter