CVE-2025-37090: HPE Storeonce System

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

Affected products

  • HPE Storeonce System: before 4.3.11 (fixed in 4.3.11)

Published 2025-06-02. Last modified 2026-06-17.