PT-2020-15775 · Hewlett Packard · Hpe Pay Per Use (Ppu) Utility Computing Service (Ucs) Meter

Published

2020-09-08

·

Updated

2020-09-29

·

CVE-2020-24624

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9
Description The issue concerns an unauthenticated directory traversal vulnerability in the DownloadServlet class execute() method. This can lead to arbitrary file reads, potentially disclosing sensitive information.
Recommendations For HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9, consider restricting access to the DownloadServlet class until a fix is available. As a temporary workaround, disabling the execute() method in the DownloadServlet class may help mitigate the risk of arbitrary file reads.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24624
ZDI-20-1098

Affected Products

Hpe Pay Per Use (Ppu) Utility Computing Service (Ucs) Meter