CVE-2020-24625

HIGH

HPE PPU UCS Meter <1.9 - Path Traversal

Title source: llm
STIX 2.1

Description

Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 62.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
hpe/utility_computing_service_meter 1.9
Published Sep 23, 2020
Tracked Since Feb 18, 2026