PT-2020-15777 · Hewlett Packard · Hpe Pay Per Use (Ppu) Utility Computing Service (Ucs) Meter

Published

2020-09-08

·

Updated

2020-09-29

·

CVE-2020-24626

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9
Description The issue concerns an unauthenticated directory traversal vulnerability in the ReceiverServlet class, specifically in the doPost() method. This can lead to arbitrary remote code execution.
Recommendations For HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9, consider restricting access to the ReceiverServlet class until a patch is available. As a temporary workaround, disabling the doPost() method in the ReceiverServlet class may help mitigate the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24626
ZDI-20-1097

Affected Products

Hpe Pay Per Use (Ppu) Utility Computing Service (Ucs) Meter