ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38475
+1 in the same advisory: …38476
Improper Output Escaping in Apache HTTP Server mod_rewrite Enables File Disclosure/Code Execution

CVE-2024-38475 is an improper escaping of output flaw (CWE-116) in the mod_rewrite module of the Apache HTTP Server. It is triggered when mod_rewrite maps a request URL to a filesystem location and mishandles encoded characters, allowing a crafted request to reach files that the server is permitted to serve but that were never intentionally or directly reachable by any URL. An attacker can abuse this to disclose source code (for example, serving raw application files) or, depending on the server's configuration and handlers, achieve code execution. Any Apache HTTP Server deployment that uses mod_rewrite is potentially affected; the source data does not specify the vulnerable version range. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01, confirming exploitation in the wild, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed.

Do: Inventory Apache HTTP Server deployments, prioritize internet-facing ones, and check whether mod_rewrite is in use (RewriteRule directives in server config, virtual hosts, or .htaccess files); upgrade to the vendor's fixed release, 2.4.60 or later. If immediate upgrade is not possible, follow vendor guidance to harden or constrain mod_rewrite rules, and treat the issue as actively exploited per CISA KEV, applying BOD 22-01 mitigations for cloud service usage or discontinuing use if mitigation is unavailable.

9.1
group max
100% KEV
  • Apache HTTP Server Version range not specified in source data; deployments with mod_rewrite enabled prior to the vendor's fixed release (2.4.60 per vendor advisory) are affected
masslikely hundreds of thousands to over a million internet-exposed Apache HTTP Server instances, with only the mod_rewrite-enabled subset vulnerable
CVE-2025-31651
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

NVD description · AI analysis pending
9.84%
  • apache tomcat
CVE-2025-37091
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

NVD description · AI analysis pending
9.8
group max
1%
  • hpe storeonce system
Full article373 words · extracted from thehackernews.com · click to collapse

The Hacker NewsJun 04, 2025Vulnerability / DevOps

Hewlett Packard Enterprise (HPE) has released security updates to address as many as eight vulnerabilities in its StoreOnce data backup and deduplication solution that could result in an authentication bypass and remote code execution.

"These vulnerabilities could be remotely exploited to allow remote code execution, disclosure of information, server-side request forgery, authentication bypass, arbitrary file deletion, and directory traversal information disclosure vulnerabilities," HPE said in an advisory.

This includes a fix for a critical security flaw tracked as CVE-2025-37093, which is rated 9.8 on the CVSS scoring system. It has been described as an authentication bypass bug affecting all versions of the software prior to 4.3.11. The vulnerability, along with the rest, was reported to the vendor on October 31, 2024.

According to the Zero Day Initiative (ZDI), which credited an anonymous researcher for discovering and reporting the shortcoming, said the problem is rooted in the implementation of the machineAccountCheck method.

"The issue results from improper implementation of an authentication algorithm," ZDI said. "An attacker can leverage this vulnerability to bypass authentication on the system."

Successful exploitation of CVE-2025-37093 could permit a remote attacker to bypass authentication on affected installations. What makes the vulnerability more severe is that it could be chained with the remaining flaws to achieve code execution, information disclosure, and arbitrary file deletion in the context of root -

  • CVE-2025-37089 - Remote Code Execution
  • CVE-2025-37090 - Server-Side Request Forgery
  • CVE-2025-37091 - Remote Code Execution
  • CVE-2025-37092 - Remote Code Execution
  • CVE-2025-37093 - Authentication Bypass
  • CVE-2025-37094 - Directory Traversal Arbitrary File Deletion
  • CVE-2025-37095 - Directory Traversal Information Disclosure
  • CVE-2025-37096 - Remote Code Execution

The disclosure comes as HPE also shipped patches to address multiple critical-severity flaws in HPE Telco Service Orchestrator (CVE-2025-31651, CVSS score: 9.8) and OneView (CVE-2024-38475, CVE-2024-38476, CVSS scores: 9.8) to address previously disclosed weaknesses in Apache Tomcat and Apache HTTP Server.

While there are no reports of active exploitation, it's essential that users apply the latest updates for optimal protection.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/06/hpe-issues-security-patch-for-storeonce.html