First published: Wed Sep 23 2020(Updated: )
Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Utility Computing Service Meter | =1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24624 has a medium severity rating due to potential unauthorized access to sensitive files.
CVE-2020-24624 exploits the system through unauthenticated directory traversal vulnerabilities in the DownloadServlet class.
The potential consequences of CVE-2020-24624 include arbitrary file reads, which may expose sensitive data.
To fix CVE-2020-24624, it is recommended to apply the latest patches provided by HPE for the Utility Computing Service Meter.
CVE-2020-24624 specifically affects HPE Utility Computing Service Meter version 1.9.