CVE-2025-37104
7.1Hewlett Packard Enterprise · Telco Service Orchestrator
HPE Telco Service Orchestrator is vulnerable to SQL injection, allowing authenticated clients to potentially exfiltrate database information via crafted service requests.
Executive summary
A high-severity SQL injection vulnerability in HPE Telco Service Orchestrator allows authenticated attackers to exfiltrate sensitive database information.
Vulnerability
This vulnerability involves a SQL injection flaw triggered by sending a malicious service request, which allows an authenticated client to access database information that should otherwise be restricted.
Business impact
The ability for an authenticated user to perform SQL injection poses a significant risk to data confidentiality and integrity. With a CVSS score of 7.1, this vulnerability indicates a high potential for unauthorized information disclosure, which could lead to further compromise of the orchestration environment and potential service disruption.
Remediation
Immediate Action: Update the HPE Telco Service Orchestrator software to version 5.2.1 or later to resolve the underlying SQL injection vulnerability.
Proactive Monitoring: Review database access logs for unusual queries or patterns associated with service requests to detect potential exploitation attempts.
Compensating Controls: Implement strict input validation or use a Web Application Firewall (WAF) to filter malicious SQL syntax from incoming service requests if immediate patching is not feasible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthorized data access, organizations should prioritize updating their HPE Telco Service Orchestrator instances to version 5.2.1 immediately. Failure to patch these systems leaves the orchestration backend exposed to malicious SQL manipulation by authenticated actors.