Database/Control plane, storage & DevOps

HPE OneView: remotely triggerable URL redirect in the management console
Impact
A vulnerability in HPE OneView can be exploited remotely to cause a URL redirect. On its own this is low severity (4.3, low confidentiality impact only), but OneView is the management console for HPE server and chassis hardware underneath GPU fleets, and an open redirect on a trusted management hostname is the standard first stage for phishing an infrastructure administrator into handing over a session - the same administrator whose session the higher-severity flaws in this advisory target. Treat it as a credibility lever against operators rather than a direct compromise of the appliance.
Who can reach it
Network, unauthenticated, but requires an operator to follow the crafted link. Anyone who can reach the OneView web interface - or craft a link to it for someone who can - can trigger the redirect.
What to do
Covered by the same OneView update as the other issues in HPE advisory HPESBGN05140; apply it and restart the appliance. No host or firmware maintenance is involved. Check the advisory for the fixed version applicable to your release.
References
Related entries
- Jenkins core: crafted XML submission lets a read-only user create user objects on the controllerCVE-2026-84646 · Jenkins core (XML deserialization, user objects as nested field values)Medium
- Jenkins core: unescaped map keys let a user inject arbitrary fields into JSON and Python API responsesCVE-2026-84655 · Jenkins core (REST API JSON and Python serialization, unescaped map keys)Medium
- Jenkins core: missing permission check exposes build parameters of jobs a user cannot otherwise seeCVE-2026-84656 · Jenkins core (build parameter access, missing Item/Read permission check)Medium
- Jenkins Script Security Plugin: form submission exposes the script approval configuration to attackersCVE-2026-84658 · Jenkins Script Security Plugin (script approval configuration)Medium
- Jenkins Script Security Plugin: missing permission check lets attackers disable global sandbox enforcementCVE-2026-84659 · Jenkins Script Security Plugin (global sandbox enforcement setting)Medium
- Jenkins LDAP plugin: Stapler data binding lets a low-privileged user make the controller connect to any URLCVE-2026-84662 · Jenkins LDAP plugin (Stapler data binding, attacker-specified connection URL)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.