Arbitrary File Read in Inspur Haiyue HCM Cloud
An unauthenticated arbitrary file read vulnerability (CVE-2024-58387) in Inspur Haiyue HCM Cloud allows remote attackers to disclose sensitive system files via the /api/model_report/file/download endpoint.
CVE search metadata
CVE search record: CVE-2024-58387. Severity: high. CVSS: 7.5. KEV: no. Product: Haiyue HCM Cloud. Brief: Arbitrary File Read in Inspur Haiyue HCM Cloud. Brief link: https://feed.craftedsignal.io/briefs/2026-09-inspur-hcm-file-read/
Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint. The flaw arises from insufficient validation of user-supplied path parameters, specifically the 'index' and 'ext' query parameters. Unauthenticated remote attackers can leverage this vulnerability to perform directory traversal, allowing them to read arbitrary files from the underlying filesystem. This risk includes the unauthorized disclosure of sensitive information such as /etc/passwd, application database files, and critical system configuration files. Evidence of exploitation in the wild was first reported by the Shadowserver Foundation on November 4, 2024. Given the nature of the vulnerability and the potential for credential harvesting or infrastructure discovery, immediate patching or restriction of access to the HCM cloud interface is recommended for organizations currently running affected versions.
Attack Chain
- Attacker performs reconnaissance to identify public-facing instances of Inspur Haiyue HCM Cloud.
- Attacker probes the /api/model_report/file/download endpoint to test for path traversal vulnerabilities.
- Attacker crafts a malicious HTTP GET request targeting the /api/model_report/file/download path.
- Attacker injects traversal sequences into the 'index' and 'ext' parameters (e.g., /api/model_report/file/download?index=/&ext=etc/passwd).
- The application fails to sanitize the input, resolving the path relative to the root directory.
- The server returns the contents of the requested file in the HTTP response body.
- Attacker parses the response to extract sensitive credentials or system configuration data.
Impact
Successful exploitation allows unauthenticated attackers to gain unauthorized access to sensitive files residing on the server. Potential consequences include the theft of system credentials (e.g., /etc/passwd), database connection strings, API keys, or configuration files that could facilitate further compromise of the internal network and HCM system data.
Recommendation
- Prioritize patching or updating Inspur Haiyue HCM Cloud to the version provided by the vendor that addresses CVE-2024-58387.
- Apply the Sigma rule below to detect exploitation attempts targeting the /api/model_report/file/download endpoint.
- Restrict access to the HCM Cloud administrative and report endpoints at the network edge to authorized IPs only.
- Monitor web server logs for HTTP GET requests containing directory traversal sequences (e.g., ../, /etc/passwd) targeting the identified vulnerable endpoint.
Immediate actions
Deploy WAF rules to block traffic containing path traversal patterns to /api/model_report/file/download
Threat Hunt
Search web server logs for HTTP 200 responses to the vulnerable endpoint containing path traversal markers
Data: Web access logs (cs-uri-stem, cs-uri-query, sc-status)
Detection coverage 1
Detects CVE-2024-58387 Exploitation - Arbitrary File Read
highDetects exploitation attempts targeting the Inspur Haiyue HCM Cloud file download endpoint by looking for directory traversal patterns in query parameters.
Detection queries are available on the platform. Get full rules →