CVE-2024-56477

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7183224 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:power_hardware_management_console:10.3.1060.0:sp1:*:*:*:*:x64:*
cpe:2.3:a:ibm:power_hardware_management_console:10.3.1060.0:sp1:*:*:*:*:x86:*

History

18 Aug 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) IBM Power Hardware Management Console V10.3.1050.0 podría permitir que un usuario autenticado recorra directorios en el sistema. Un atacante podría enviar una solicitud de URL especialmente manipulada que contenga secuencias de "punto punto" (/../) para ver archivos arbitrarios en el sistema.
CPE cpe:2.3:a:ibm:power_hardware_management_console:10.3.1060.0:sp1:*:*:*:*:x86:*
cpe:2.3:a:ibm:power_hardware_management_console:10.3.1060.0:sp1:*:*:*:*:x64:*
First Time Ibm
Ibm power Hardware Management Console
References () https://www.ibm.com/support/pages/node/7183224 - () https://www.ibm.com/support/pages/node/7183224 - Vendor Advisory

14 Feb 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-14 15:15

Updated : 2025-08-18 18:15


NVD link : CVE-2024-56477

Mitre link : CVE-2024-56477

CVE.ORG link : CVE-2024-56477


JSON object : View

Products Affected

ibm

  • power_hardware_management_console
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')