Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

HPE Patches Critical Flaw in IT Infrastructure Management Software

Tracked as CVE-2025-37164, the critical flaw could allow unauthenticated, remote attackers to execute arbitrary code.

HPE vulnerability

Hewlett Packard Enterprise (HPE) this week announced patches for a critical-severity remote code execution vulnerability in its OneView IT infrastructure management software.

Tracked as CVE-2025-37164 (CVSS score of 10), the security defect can be exploited without authentication, the company notes in a barebones advisory.

HPE makes no mention of the flaw being exploited in the wild, but urges customers to update to a fixed release as soon as possible.

According to HPE, the issue impacts all OneView releases up to version 10.20. The company has released hotfixes for OneView users and recommends updating 6.60.xx iterations to version 7.00 prior to applying the patch. HPE Synergy Composer reimages should also be updated.

The HPE OneView virtual appliance security hotfixes are available on this page, while the HPE Synergy CVE security hotfix can be found here.

Rapid7 says:

Advertisement. Scroll to continue reading.

“This hotfix applies a new HTTP rule to the appliance’s webserver to block access to a specific REST API endpoint. This endpoint is /rest/id-pools/executeCommand. Initial inspection of the appliance code indicates this endpoint is reachable without authentication. Rapid7 Labs assesses with a high degree of confidence that this is the access vector for triggering the vulnerability and achieving remote code execution.”

HPE refrained from releasing technical details on the weakness but credited Nguyen Quoc Khanh for reporting it.

This week, HPE also rolled out fixes for three vulnerabilities in dependencies used in the Telco Service Activator service provisioning and activation software platform.

Tracked as CVE-2025-49146, CVE-2025-55163, and CVE-2025-7962, the issues impact the open source PostgreSQL JDBC driver PgJDBC, the Netty network application framework, and Jakarta Mail.

Successful exploitation of the bugs, the company says, could lead to authentication bypass, denial-of-service (DoS), and Carriage Return Line Feed (CRLF) injection.

All HPE Telco Service Activator versions up to 10.3.2 are affected. Patches for the three security defects were included in version 10.3.3 of the platform.

Neither of these vulnerabilities appears to have been exploited in attacks targeting HPE Telco Service Activator users.

*Updated with information from Rapid7 and to correct affected OneView versions, after HPE updated their advisory.

Related: CISA Warns of Exploited Flaw in Asus Update Tool

Related: SonicWall Patches Exploited SMA 1000 Zero-Day

Related: JumpCloud Remote Assist Vulnerability Can Expose Systems to Takeover

Related: Atlassian Patches Critical Apache Tika Flaw

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.