CVE-2024-56477

Publication date

2025-02-14 14:49:45

Family

ibm

State

PUBLISHED

Description

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.