Database/Control plane, storage & DevOps
HPE Insight Remote Support: XML external entity injection allows remote disclosure of server information
Impact
An unauthenticated remote attacker can submit crafted XML to Insight Remote Support and read files or other information from the IRS server. HPE assigned three separate ids (CVE-2024-11622, CVE-2024-53674, CVE-2024-53675) to distinct XXE parsing paths, but all are the same flaw class in the same component with the same effect and the same fix.
Who can reach it
Unauthenticated network access.
What to do
Apply the update in HPE advisory HPESBGN04731 (Insight Remote Support 7.14.0.629 or later); the single patch closes all three XXE ids at once.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- AMD Optimizing CPU Libraries (AOCL) - installation directory permissions: AOCL installs with permissive directoryCVE-2024-21960 · AMD Optimizing CPU Libraries (AOCL) - installation directory permissionsHigh
- Intel Data Center GPU Flex Series - Windows driver: Improper buffer restrictions in the Flex Series Windows driver letCVE-2024-36292 · Intel Data Center GPU Flex Series - Windows driverHigh
- AMD Optimizing CPU Libraries (AOCL) - DLL hijacking: A DLL search-order hijack in AOCL lets an attacker getCVE-2024-36339 · AMD Optimizing CPU Libraries (AOCL) - DLL hijackingHigh
- Dell OpenManage Server Administrator (XSL hijacking local privilege escalation): A local low-privileged user hijacksCVE-2024-37130 · Dell OpenManage Server Administrator (XSL hijacking local privilege escalation)High
- Intel Data Center GPU Flex Series - Windows driver: A further improper access control in the Flex Series Windows driverCVE-2024-45333 · Intel Data Center GPU Flex Series - Windows driverHigh
- Nx @nx/docker: config-controlled shell injection in release commands executes code in the release jobCVE-2026-104859 · Nx @nx/docker release pipeline (repositoryName / registryUrl shell interpolation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.