CVEs Blog | G5 Cyber Security

CVE-2020-24624 – Unathenticated directory traversal in the DownloadServlet class execute()

Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24624

Reference (s):

Exit mobile version