CVE-2025-37104

A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clients.
Configurations

No configuration.

History

18 Jul 2025, 15:15

Type Values Removed Values Added
CWE CWE-89

17 Jul 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad de seguridad en el software HPE Telco Service Orchestrator. Esta vulnerabilidad podría permitir que clientes autenticados realicen un ataque de inyección SQL al enviar una solicitud de servicio y, potencialmente, exfiltren el nombre del proveedor de la base de datos a clientes autenticados no autorizados.

16 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-16 15:15

Updated : 2025-07-18 15:15


NVD link : CVE-2025-37104

Mitre link : CVE-2025-37104

CVE.ORG link : CVE-2025-37104


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')