To fix up to eight flaws in its StoreOnce data backup and deduplication solution that might lead to remote code execution and authentication circumvention, Hewlett Packard Enterprise (HPE) has issued security patches.
According to an alert from HPE, these vulnerabilities might be remotely exploited to enable arbitrary file deletion, server-side request forgery, remote code execution, information disclosure, and directory traversal issues.
Included in this is a patch for a serious security vulnerability known as CVE-2025-37093, which has a CVSS score of 9.8. All software versions before 4.3.11 were reportedly affected by this authentication bypass problem. On October 31, 2024, the vendor was notified of the vulnerability and the others.
The Zero Day Initiative (ZDI), which gave credit to an unnamed researcher for identifying and disclosing the vulnerability read more about HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
