OneView
by HPE
CVEs (29)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-37164 | Cri | 0.87 | 10.0 | 0.90 | KEV | Dec 16, 2025 | A remote code execution issue exists in HPE OneView. | |
| CVE-2024-22442 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | The vulnerability could be remotely exploited to bypass authentication. | ||
| CVE-2023-30909 | Cri | 0.64 | 9.8 | 0.02 | Sep 14, 2023 | A remote authentication bypass issue exists in some OneView APIs. | ||
| CVE-2023-30908 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2023 | A remote authentication bypass issue exists in a OneView API. | ||
| CVE-2022-28616 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2022 | A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2022-28617 | Cri | 0.64 | 9.8 | 0.02 | May 17, 2022 | A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2020-7198 | Hig | 0.57 | 8.8 | 0.02 | Nov 6, 2020 | There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2. | ||
| CVE-2026-76719 | Hig | 0.53 | 8.2 | 0.00 | Sep 29, 2026 | A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. | ||
| CVE-2026-76718 | Hig | 0.53 | 8.2 | 0.00 | Sep 29, 2026 | A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. | ||
| CVE-2023-50274 | Hig | 0.51 | 7.8 | 0.01 | Jan 23, 2024 | HPE OneView may allow command injection with local privilege escalation. | ||
| CVE-2023-28088 | Hig | 0.51 | 7.8 | 0.00 | Apr 25, 2023 | An HPE OneView appliance dump may expose SAN switch administrative credentials | ||
| CVE-2022-23699 | Hig | 0.51 | 7.8 | 0.00 | Apr 4, 2022 | A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2023-50275 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2024 | HPE OneView may allow clusterService Authentication Bypass resulting in denial of service. | ||
| CVE-2022-23698 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2022 | A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2023-30912 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2023 | A remote code execution issue exists in HPE OneView. | ||
| CVE-2023-28089 | Hig | 0.46 | 7.1 | 0.00 | Apr 25, 2023 | An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules | ||
| CVE-2026-23596 | Med | 0.42 | 6.5 | 0.00 | Feb 17, 2026 | A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability. | ||
| CVE-2022-23706 | Med | 0.40 | 6.1 | 0.01 | May 17, 2022 | A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2022-23697 | Med | 0.40 | 6.1 | 0.01 | Apr 4, 2022 | A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2024-42508 | Med | 0.36 | 5.5 | 0.00 | Oct 18, 2024 | This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users. |
- risk 0.87cvss 10.0epss 0.90
A remote code execution issue exists in HPE OneView.
- risk 0.64cvss 9.8epss 0.01
The vulnerability could be remotely exploited to bypass authentication.
- risk 0.64cvss 9.8epss 0.02
A remote authentication bypass issue exists in some OneView APIs.
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass issue exists in a OneView API.
- risk 0.64cvss 9.8epss 0.01
A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.64cvss 9.8epss 0.02
A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.57cvss 8.8epss 0.02
There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.
- risk 0.53cvss 8.2epss 0.00
A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.
- risk 0.53cvss 8.2epss 0.00
A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions.
- risk 0.51cvss 7.8epss 0.01
HPE OneView may allow command injection with local privilege escalation.
- risk 0.51cvss 7.8epss 0.00
An HPE OneView appliance dump may expose SAN switch administrative credentials
- risk 0.51cvss 7.8epss 0.00
A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.49cvss 7.5epss 0.01
HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
- risk 0.49cvss 7.5epss 0.01
A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.47cvss 7.2epss 0.01
A remote code execution issue exists in HPE OneView.
- risk 0.46cvss 7.1epss 0.00
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
- risk 0.42cvss 6.5epss 0.00
A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability.
- risk 0.40cvss 6.1epss 0.01
A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.40cvss 6.1epss 0.01
A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.36cvss 5.5epss 0.00
This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.
Page 1 of 2