CVE-2020-24625: Path Traversal
Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24625?
CVE-2020-24625 is a vulnerability in the ReceiverServlet class doGet() method in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9 that allows unauthenticated directory traversal and arbitrary file reads.
How severe is CVE-2020-24625?
CVE-2020-24625 has a severity score of 7.5 (high), indicating a significant threat.
Which software is affected by CVE-2020-24625?
HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9 is affected by CVE-2020-24625.
How can the vulnerability be exploited?
The vulnerability can be exploited by performing unauthenticated directory traversal and arbitrary file reads through the ReceiverServlet class doGet() method.
Is there a fix available for CVE-2020-24625?
To fix CVE-2020-24625, it is recommended to apply the necessary updates provided by HPE Utility Computing Service Meter.