Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hpe
Published: 2020-09-23T12:41:00
Updated: 2024-08-04T15:19:08.970Z
Reserved: 2020-08-25T00:00:00
Link: CVE-2020-24624
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-23T13:15:15.640
Modified: 2024-11-21T05:15:14.487
Link: CVE-2020-24624
Redhat
No data.