High severity7.5NVD Advisory· Published Sep 23, 2020· Updated Jun 17, 2026
CVE-2020-24624
CVE-2020-24624
Description
Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
Affected products
3- cpe:2.3:a:hpe:utility_computing_service_meter:1.9:*:*:*:pay_per_use:*:*:*
- HPE/Pay Per Use (PPU) Utility Computing Service (UCS) Meterdescription
- Range: = 1.9
Patches
Vulnerability mechanics
References
1- support.hpe.com/hpsc/doc/public/displaynvdVendor Advisory
News mentions
0No linked articles in our index yet.