Impact
The vulnerability is a path traversal flaw in the Performance Co-Pilot (PCP) pmproxy logger servlet that can be triggered by an unauthenticated remote attacker using a specially crafted hostname. This flaw allows the attacker to create arbitrary files or directories on the host system. The ability to write to arbitrary locations can disrupt system operation and may lead to a denial of service, especially if critical logging or configuration files are overwritten or deleted. The weakness is categorized as CWE‑22: Path Traversal.
Affected Systems
The flaw affects Red Hat Enterprise Linux releases 6 through 10 and OpenShift Container Platform 4. These systems run the pmproxy service, which listens on TCP port 44322. Any configuration that exposes this service to untrusted networks is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability, and the EPSS score is <1 %, suggesting a low current exploit likelihood. The flaw is unauthenticated and network-based, targeting the pmproxy service. Because the attacker can create arbitrary files, the risk is concentrated on disrupting the pmproxy logging mechanism, potentially causing a denial of service for dependent Performance Co‑Pilot components. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment