Database/Control plane, storage & DevOps
HPE Insight Remote Support (path traversal): Unauthenticated path traversal disclosing files from the IRS server
CVSS 7.5CVE-2025-37098Control plane, storage & DevOpscurated
Impact
Unauthenticated path traversal disclosing files from the IRS server - including configuration holding device credentials.
Who can reach it
Unauthenticated network access below v7.15.0.646.
What to do
Upgrade Insight RS to 7.15.0.646 and rotate any device credentials stored in its configuration.
References
Related entries
- Citrix NetScaler ADC/Gateway: "CitrixBleed 2" - insufficient input validationCVE-2025-5777 · Citrix NetScaler ADC/GatewayHigh
- Go crypto/x509 (Tailscale, Go infra): Name-constraint checking scales non-linearly with certificate sizeCVE-2025-58187 · Go crypto/x509 (Tailscale, Go infra)High
- Apache DolphinScheduler: exposed management endpoints leak database credentials to unauthenticated callersCVE-2025-62188 · Apache DolphinScheduler 3.1.x (exposed Spring Boot management endpoints)High
- Apache Airflow: pre-3.2 deployments lack the isolation guarantees operators assumed, per clarified security modelCVE-2025-66236 · Apache Airflow (workload isolation and JWT token authentication, deployments before 3.2.0)High
- IBM Storage Scale GUI (hardcoded inter-node token): A hardcoded token in the Storage Scale GUI source, usedCVE-2026-13460 · IBM Storage Scale GUI (hardcoded inter-node token)High
- Performance Co-Pilot: signed integer overflow in __pmGetPDU permanently blinds the collector daemonCVE-2026-16529 · Performance Co-Pilot pmcd/PMAPI (__pmGetPDU PDU length handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.