ZDI-25-313: Hewlett Packard Enterprise StoreOnce VSA determineInclusionAndExtract Server-Side Request Forgery Vulnerability
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Hewlett Packard Enterprise StoreOnce VSA. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2025-37090.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-313?
The severity of ZDI-25-313 is rated at 5.3 on the CVSS scale.
How do I fix ZDI-25-313?
To fix ZDI-25-313, apply the latest security patches provided by Hewlett Packard Enterprise for StoreOnce VSA.
Can ZDI-25-313 be exploited without authentication?
Yes, ZDI-25-313 can be exploited without any authentication required.
What types of attacks are possible due to ZDI-25-313?
ZDI-25-313 allows remote attackers to initiate arbitrary server-side requests, potentially leading to further system compromise.
Which products are affected by ZDI-25-313?
ZDI-25-313 affects installations of Hewlett Packard Enterprise StoreOnce VSA.