Cisco HyperFlex HX Data Platform contains an arbitrary file upload vulnerability in the web-based management interface. An attacker can send a specific HTTP request to an affected device, thus enabling upload of files to the affected device with the permissions of the tomcat8 user.
id: CVE-2021-1499
info:
name: Cisco HyperFlex HX Data Platform - Arbitrary File Upload
author:
...