By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
Computing

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

News Room
Last updated: 2025/12/18 at 11:13 AM
News Room Published 18 December 2025
Share
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
SHARE

Dec 18, 2025Ravie LakshmananVulnerability / Enterprise Security

Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in OneView Software that, if successfully exploited, could result in remote code execution.

The critical vulnerability, assigned the CVE identifier CVE-2025-37164, carries a CVSS score of 10.0. HPE OneView is an IT infrastructure management software that streamlines IT operations and controls all systems via a centralized dashboard interface.

“A potential security vulnerability has been identified in Hewlett Packard Enterprise OneView Software. This vulnerability could be exploited, allowing a remote unauthenticated user to perform remote code execution,” HPE said in an advisory issued this week.

Cybersecurity

It affects all versions of the software prior to version 11.00, which addresses the flaw. The company has also made available a hotfix that can be applied to OneView versions 5.20 through 10.20.

It’s worth noting that the hotfix must be reapplied after upgrading from version 6.60 or later to version 7.00.00, or after any HPE Synergy Composer reimaging operations. Separate hotfixes are available for the OneView virtual appliance and Synergy Composer2.

Although HPE makes no mention of the flaw being exploited in the wild, it’s essential that users apply the patches as soon as possible for optimal protection.

Earlier this June, the company also released updates to fix eight vulnerabilities in its StoreOnce data backup and deduplication solution that could result in an authentication bypass and remote code execution. It also shipped OneView version 10.00 to remediate a number of known flaws in third-party components, such as Apache Tomcat and Apache HTTP Server.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Report: CEOs Will Keep Spending On AI Despite Poor Returns Report: CEOs Will Keep Spending On AI Despite Poor Returns
Next Article Microsoft’s holiday Copilot ad is wrapped in empty promises Microsoft’s holiday Copilot ad is wrapped in empty promises
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Exein closes €100M round to harden security in internet of things devices –  News
Exein closes €100M round to harden security in internet of things devices – News
News
JEP 500: Java to Enforce Strict Final Field Immutability by Restricting Reflection
JEP 500: Java to Enforce Strict Final Field Immutability by Restricting Reflection
News
Who is the winner of ‘Survivor’ season 49? Everything about former news anchor Savannah Louie
Who is the winner of ‘Survivor’ season 49? Everything about former news anchor Savannah Louie
News
With new Alexa website, Amazon’s consumer AI vision finally comes together — and it’s actually useful
With new Alexa website, Amazon’s consumer AI vision finally comes together — and it’s actually useful
Computing

You Might also Like

With new Alexa website, Amazon’s consumer AI vision finally comes together — and it’s actually useful
Computing

With new Alexa website, Amazon’s consumer AI vision finally comes together — and it’s actually useful

5 Min Read
AMD Radeon RX 9000 Series vs. NVIDIA GeForce RTX 50 Open-Source Linux Performance For 2025
Computing

AMD Radeon RX 9000 Series vs. NVIDIA GeForce RTX 50 Open-Source Linux Performance For 2025

3 Min Read
Kuaishou e-commerce abolishes refund-without-return policy after long-running merchant complaints · TechNode
Computing

Kuaishou e-commerce abolishes refund-without-return policy after long-running merchant complaints · TechNode

4 Min Read
Why a high-profile discrimination case against Kuda was dismissed
Computing

Why a high-profile discrimination case against Kuda was dismissed

7 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?