Database/Control plane, storage & DevOps

HPE StoreOnce (command injection RCE): Unauthenticated remote code execution on the backup appliance
CVE-2025-37089Control plane, storage & DevOpscurated
Impact
Unauthenticated remote code execution on the backup appliance.
Who can reach it
Unauthenticated network access to StoreOnce.
What to do
Upgrade StoreOnce per HPESBST04847. Ships with the auth-bypass fix in the same update.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.