A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clients.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 18 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 14:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clients.
Title HPE Telco Service Orchestrator Software, Authenticated SQL Injection
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-07-18T14:52:06.009Z

Reserved: 2025-04-16T01:28:25.364Z

Link: CVE-2025-37104

cve-icon Vulnrichment

Updated: 2025-07-18T14:52:02.579Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-16T15:15:26.520

Modified: 2025-07-18T15:15:26.397

Link: CVE-2025-37104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.