First published: Thu Feb 13 2025(Updated: )
IBM Hardware Management Console - Power could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Power Hardware Management Console Firmware | ||
IBM HMC | <=V10.3.1050.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56477 is considered a moderate severity vulnerability as it allows authenticated users to traverse directories on the system.
To fix CVE-2024-56477, ensure that you update the IBM Power Hardware Management Console to the latest version available.
CVE-2024-56477 affects users of IBM Power Hardware Management Console, specifically versions up to and including V10.3.1050.0.
CVE-2024-56477 allows an attacker to perform directory traversal attacks, potentially accessing arbitrary files on the system.
The impact of CVE-2024-56477 includes unauthorized access to sensitive files, which could lead to data breaches or information disclosure.