Database/Control plane, storage & DevOps

HPE OneView for VMware vCenter (vertical privilege escalation): A read-only user performs administrative actions
CVE-2025-37101Control plane, storage & DevOpscurated
Impact
A read-only user performs administrative actions through the OneView vCenter plugin - so view-only access to vCenter becomes administrative control over HPE hardware management.
Who can reach it
Authenticated read-only user of the OV4VC plugin, with user interaction.
What to do
Apply the HPE update per HPESBGN04876. Plugin update inside vCenter; no server firmware work.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.