Friday, 17 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > HPE OneView vulnerable to remote code execution attack
Global Market

HPE OneView vulnerable to remote code execution attack

Last updated: December 19, 2025 3:41 am
Published December 19, 2025
Share
A photograph of a building with the HPE logo on the facade.
SHARE

The advisory provides that any third get together safety patches which can be to be put in on methods working HPE software program merchandise needs to be utilized in accordance with the shopper’s patch administration coverage.

Requested for remark, an HPE spokesperson stated the corporate has nothing to say past its advisory, apart from to induce admins to obtain and set up the patches as quickly as doable.

Jack Bicer, director of vulnerability analysis at Action1, stated that as a result of this vulnerability may be exploited with out authentication or any consumer interplay, it’s “an especially extreme safety concern. There are not any out there workarounds, so the patch needs to be utilized instantly. Till the patch may be utilized, prohibit community entry to the OneView administration interface to trusted administrative networks solely.”

HPE describes OneView as an answer that simplifies infrastructure lifecycle administration throughout compute storage and networking by way of a unified API. It permits admins to create a list of workload-optimized infrastructure templates so extra common IT employees can quickly and reliably provision assets. These templates can rapidly provision bodily, digital, and containerized methods, organising BIOS settings, native RAID configuration, firmware baseline, shared storage and extra. HPE says software-defined intelligence permits IT to run a number of purposes concurrently with repeatable templates that guarantee excessive reliability, consistency, and management. The seller additionally says the embedded automation speeds provisioning and lowers working bills.

The latest main vulnerability in OneView was revealed in June: CVE-2025-37101, an area elevation of privilege concern which relates particularly to OneView for VMware vCenter. If exploited, an attacker with learn solely privilege may improve their entry to permit them to carry out admin actions.

See also  Upskilling is key to democratising AI

This text initially appeared on CSOonline.

Source link

TAGGED: attack, Code, Execution, HPE, OneView, Remote, vulnerable
Share This Article
Twitter Email Copy Link Print
Previous Article AI in Human Resources: the real operational impact AI in Human Resources: the real operational impact
Next Article Palona goes vertical, launching Vision, Workflow features: 4 key lessons for AI builders Palona goes vertical, launching Vision, Workflow features: 4 key lessons for AI builders
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Prometheum Raises $20M in Funding

Prometheum, a NYC-based market infrastructure supplier for digital asset securities, raised $20M in funding. Backers…

December 18, 2024

Samsung opens lab dedicated to next-gen AI chips

Ultimately, Samsung plans to repeatedly launch new variations of AGI Computing Lab chip designs in…

March 20, 2024

Versa Networks selected for DISA’s Thunderdome Program

“We’re deeply thrilled to be selected as part of Thunderdome, which is pioneering the application…

January 22, 2024

Cloud continues to enable innovation in tough economic climate, says Cloud Industry Forum

100% of organisations at the moment are accessing cloud-based providers to fulfill their wants, with…

May 21, 2024

New all-optical approach could miniaturize night vision technology

Infrared (IR) to seen (VIS) up-conversion for imaginative and prescient functions. a) Schematic of the…

June 3, 2024

You Might Also Like

3D zero-day vulnerability refers to a security flaw in software
Global Market

DNS security is often inadequate, and network engineers should get more involved

By saad
Agenetic AI will transform IT operations
Global Market

AI shifts IT roles from operator to orchestrator

By saad
OpenAI Agents SDK improves governance with sandbox execution
AI

OpenAI Agents SDK improves governance with sandbox execution

By saad
Spending on AI-enabled security tools
Global Market

IBM unveils security services for thwarting agentic attacks, automating threat assessment

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.