Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
References
Link | Resource |
---|---|
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04037en_us | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: hpe
Published: 2020-09-23T12:41:19
Updated: 2020-09-23T12:41:19
Reserved: 2020-08-25T00:00:00
Link: CVE-2020-24626
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-09-23T13:15:15.780
Modified: 2020-09-29T18:07:22.597
Link: CVE-2020-24626
JSON object: View
Redhat Information
No data.
CWE