Database/Control plane, storage & DevOps
HPE Insight Remote Support (Java deserialization): Java deserialization letting an unauthenticated attacker execute
CVSS 8.1CVE-2024-53673Control plane, storage & DevOpscurated
Impact
Java deserialization letting an unauthenticated attacker execute code on the Insight RS server.
Who can reach it
Unauthenticated network access.
What to do
Patch per HPESBGN04731 alongside the other IRS issues in the same bulletin.
References
Related entries
- PostgreSQL (libpq): Improper quoting in PQescape*CVE-2025-1094 · PostgreSQL (libpq)High
- HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUICVE-2025-27086 · HPE Performance Cluster Manager (HPCM) GUI authentication bypassHigh
- HTCondor (IDToken authorization restrictions): The per-token authorization restrictions attached withCVE-2025-30093 · HTCondor (IDToken authorization restrictions)High
- ConnectWise ScreenConnect: ViewState code injectionCVE-2025-3935 · ConnectWise ScreenConnectHigh
- MinIO (service accounts / STS session policies): The session policy attached to a service account or STS credential isCVE-2025-62506 · MinIO (service accounts / STS session policies)High
- Apache CloudStack: MinIO policies survive bucket deletion, giving a former owner access to a new bucket of the same nameCVE-2025-66467 · Apache CloudStack (MinIO object store policy cleanup on bucket deletion)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.