CVE-2025-37105

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hpe:autopass_license_server:*:*:*:*:*:*:*:*

History

25 Jul 2025, 15:28

Type Values Removed Values Added
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04877en_us - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04877en_us - Vendor Advisory
First Time Hpe
Hpe autopass License Server
CPE cpe:2.3:a:hpe:autopass_license_server:*:*:*:*:*:*:*:*

18 Jul 2025, 15:15

Type Values Removed Values Added
CWE CWE-94

17 Jul 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de ejecución de código remoto relacionada con hsqldb en HPE AutoPass License Server (APLS) anterior a la versión 9.18.

16 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-16 18:15

Updated : 2025-07-25 15:28


NVD link : CVE-2025-37105

Mitre link : CVE-2025-37105

CVE.ORG link : CVE-2025-37105


JSON object : View

Products Affected

hpe

  • autopass_license_server
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')