Database/Control plane, storage & DevOps

HPE StoreOnce (server-side request forgery): SSRF from the backup appliance, letting an unauthenticated attacker pivot
CVE-2025-37090Control plane, storage & DevOpscurated
Impact
SSRF from the backup appliance, letting an unauthenticated attacker pivot requests into internal networks the appliance can reach.
Who can reach it
Unauthenticated network access.
What to do
Upgrade StoreOnce per HPESBST04847.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.