Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

HPE Patches Critical Flaw in IT Infrastructure Management Software

Posted on December 18, 2025December 18, 2025 By CWS

Hewlett Packard Enterprise (HPE) this week introduced patches for a critical-severity distant code execution vulnerability in its OneView IT infrastructure administration software program.

Tracked as CVE-2025-37164 (CVSS rating of 10), the safety defect could be exploited with out authentication, the corporate notes in a barebones advisory.

HPE makes no point out of the flaw being exploited within the wild, however urges prospects to replace to a set launch as quickly as potential.

In response to HPE, the difficulty impacts all OneView releases as much as model 10.20. The corporate has launched hotfixes for OneView customers and recommends updating 6.60.xx iterations to model 7.00 previous to making use of the patch. HPE Synergy Composer reimages also needs to be up to date.

The HPE OneView digital equipment safety hotfixes can be found on this web page, whereas the HPE Synergy CVE safety hotfix could be discovered right here.

HPE shunned releasing technical particulars on the weak spot however credited Nguyen Quoc Khanh for reporting it.

This week, HPE additionally rolled out fixes for 3 vulnerabilities in dependencies used within the Telco Service Activator service provisioning and activation software program platform.

Tracked as CVE-2025-49146, CVE-2025-55163, and CVE-2025-7962, the problems impression the open supply PostgreSQL JDBC driver PgJDBC, the Netty community utility framework, and Jakarta Mail.Commercial. Scroll to proceed studying.

Profitable exploitation of the bugs, the corporate says, may result in authentication bypass, denial-of-service (DoS), and Carriage Return Line Feed (CRLF) injection.

All HPE Telco Service Activator variations as much as 10.3.2 are affected. Patches for the three safety defects had been included in model 10.3.3 of the platform.

Neither of those vulnerabilities seems to have been exploited in assaults concentrating on HPE Telco Service Activator customers.

Associated: CISA Warns of Exploited Flaw in Asus Replace Software

Associated: SonicWall Patches Exploited SMA 1000 Zero-Day

Associated: JumpCloud Distant Help Vulnerability Can Expose Methods to Takeover

Associated: Atlassian Patches Crucial Apache Tika Flaw

Security Week News Tags:Critical, Flaw, HPE, Infrastructure, Management, Patches, Software

Post navigation

Previous Post: HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
Next Post: UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks

Related Posts

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw Security Week News
Russian Government Hackers Caught Buying Passwords from Cybercriminals Security Week News
Cyberstarts Launches $300M Liquidity Fund to Help Startups Retain Top Talent Security Week News
Verisoul Raises $8.8 Million for Fraud Prevention Security Week News
Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case Security Week News
How TTP-based Defenses Outperform Traditional IoC Hunting Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
  • New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector
  • UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
  • HPE Patches Critical Flaw in IT Infrastructure Management Software
  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
  • New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector
  • UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
  • HPE Patches Critical Flaw in IT Infrastructure Management Software
  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark