ZDI-24-1632: Hewlett Packard Enterprise AutoPass License Server hsqldb Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Hewlett Packard Enterprise AutoPass License Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2024-51768.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1632?
The severity of ZDI-24-1632 is critical due to the potential for arbitrary code execution.
How do I fix ZDI-24-1632?
To fix ZDI-24-1632, apply the latest patches from Hewlett Packard Enterprise for the AutoPass License Server.
Who is affected by ZDI-24-1632?
Hewlett Packard Enterprise AutoPass License Server installations are affected by ZDI-24-1632.
Can ZDI-24-1632 be exploited remotely?
Yes, ZDI-24-1632 can be exploited by network-adjacent attackers if they bypass the authentication mechanism.
What types of attacks does ZDI-24-1632 enable?
ZDI-24-1632 enables attackers to execute arbitrary code on affected installations.