Critical severity9.8NVD Advisory· Published Sep 23, 2020· Updated Jun 17, 2026
CVE-2020-24626
CVE-2020-24626
Description
Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
Affected products
3- HPE/Pay Per Use (PPU) Utility Computing Service (UCS) Meterdescription
- cpe:2.3:a:hpe:utility_computing_service_meter:1.9:*:*:*:pay_per_use:*:*:*
- Range: = 1.9
Patches
Vulnerability mechanics
References
1- support.hpe.com/hpsc/doc/public/displaynvdVendor Advisory
News mentions
0No linked articles in our index yet.