CVE-2025-37105: HPE Autopass License Server

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

Affected products

  • HPE Autopass License Server: before 9.18 (fixed in 9.18)

Published 2025-07-16. Last modified 2026-06-17.