PT-2025-23515 · Hewlett Packard · Hpe Storeonce

John Doe

·

Published

2024-10-31

·

Updated

2025-07-02

·

CVE-2025-37090

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE StoreOnce Software (affected versions not specified)
Description A server-side request forgery vulnerability exists in HPE StoreOnce Software. This issue allows for exploitation through specific API endpoints, although the exact endpoints are not specified. No information is provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-06382
CVE-2025-37090
ZDI-25-313

Affected Products

Hpe Storeonce