CVE-2025-37104 - CERT CVE
ID CVE-2025-37104
Sažetak A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clients.
Reference
CVSS
Base: 7.1
Impact: 5.3
Exploitability:1.3
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
LOW HIGH LOW
CVSS vektor CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
Zadnje važnije ažuriranje 17-07-2025 - 21:15
Objavljeno 16-07-2025 - 15:15