CVE-2025-37087: Hewlett Packard Enterprise HPE HPE Performance Cluster Manager Hpcm

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.

Affected products

Published 2025-04-22. Last modified 2026-06-17.