CVE-2024-56477: IBM Power Hardware Management Console directory traversal
IBM Hardware Management Console - Power could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Other sources
IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56477?
CVE-2024-56477 is considered a moderate severity vulnerability as it allows authenticated users to traverse directories on the system.
How do I fix CVE-2024-56477?
To fix CVE-2024-56477, ensure that you update the IBM Power Hardware Management Console to the latest version available.
Who is affected by CVE-2024-56477?
CVE-2024-56477 affects users of IBM Power Hardware Management Console, specifically versions up to and including V10.3.1050.0.
What type of attack is enabled by CVE-2024-56477?
CVE-2024-56477 allows an attacker to perform directory traversal attacks, potentially accessing arbitrary files on the system.
What is the impact of CVE-2024-56477?
The impact of CVE-2024-56477 includes unauthorized access to sensitive files, which could lead to data breaches or information disclosure.