CVE-2025-37104

7.1

Hewlett Packard Enterprise · Telco Service Orchestrator

HPE Telco Service Orchestrator is vulnerable to SQL injection, allowing authenticated clients to potentially exfiltrate database information via crafted service requests.

Executive summary

A high-severity SQL injection vulnerability in HPE Telco Service Orchestrator allows authenticated attackers to exfiltrate sensitive database information.

Vulnerability

This vulnerability involves a SQL injection flaw triggered by sending a malicious service request, which allows an authenticated client to access database information that should otherwise be restricted.

Business impact

The ability for an authenticated user to perform SQL injection poses a significant risk to data confidentiality and integrity. With a CVSS score of 7.1, this vulnerability indicates a high potential for unauthorized information disclosure, which could lead to further compromise of the orchestration environment and potential service disruption.

Remediation

Immediate Action: Update the HPE Telco Service Orchestrator software to version 5.2.1 or later to resolve the underlying SQL injection vulnerability.

Proactive Monitoring: Review database access logs for unusual queries or patterns associated with service requests to detect potential exploitation attempts.

Compensating Controls: Implement strict input validation or use a Web Application Firewall (WAF) to filter malicious SQL syntax from incoming service requests if immediate patching is not feasible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized data access, organizations should prioritize updating their HPE Telco Service Orchestrator instances to version 5.2.1 immediately. Failure to patch these systems leaves the orchestration backend exposed to malicious SQL manipulation by authenticated actors.

More Hewlett Packard Enterprise CVEs

Sources