CVE-2025-37090: SSRF
Published Jun 2, 2025
·Updated
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
Affected Software
2 affected components
Hewlett Packard Enterprise StoreOnce
HPE Storeonce System<4.3.11
Event History
Jun 2, 2025
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37090?
CVE-2025-37090 is classified as a critical severity vulnerability.
2
How do I fix CVE-2025-37090?
To fix CVE-2025-37090, apply the latest security patch provided by HPE for StoreOnce Software.
3
What is a server-side request forgery in the context of CVE-2025-37090?
In the context of CVE-2025-37090, server-side request forgery allows an attacker to send unauthorized requests from the vulnerable server.
4
Which version of HPE StoreOnce Software is affected by CVE-2025-37090?
CVE-2025-37090 affects all versions of HPE StoreOnce Software.
5
Is there a workaround for CVE-2025-37090?
Currently, there are no documented workarounds for CVE-2025-37090, and applying the patch is the recommended approach.