Known vulnerabilities in AutoPass License Server (APLS)
Vendor:
HPE
Software:
AutoPass License Server (APLS)
Software CPE:
cpe:2.3:a:hpe:autopass_license_server_apls:*:*:*:*:*:*:*:*
Website:
https://www.hpe.com
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU113084 - Improper Authentication CVE-2025-37107 |
CWE-287 | Medium | 9.18 | 21.07.2025 |
SB2025072115 |
||
| #VU113083 - Improper Authentication CVE-2025-37106 |
CWE-287 | Medium | 9.18 | 21.07.2025 |
SB2025072115 |
||
| #VU113082 - Improper Control of Generation of Code ('Code Injection') CVE-2025-37105 |
CWE-94 | Medium | 9.18 | 21.07.2025 |
SB2025072115 |
||
| #VU101117 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2024-51770 |
CWE-611 | Medium | 9.17 | 03.12.2024 |
SB2024120322 SB2025020450 |
||
| #VU101115 - Improper Control of Generation of Code ('Code Injection') CVE-2024-51768 |
CWE-94 | Medium | 9.17 | 03.12.2024 |
SB2024120322 SB2025020450 |
||
| #VU101100 - Improper Authentication CVE-2024-51767 |
CWE-287 | Medium | 9.17 | 03.12.2024 |
SB2024120322 SB2025020450 |
||
| #VU101095 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-51769 |
CWE-89 | Medium | 9.17 | 03.12.2024 |
SB2024120322 SB2025020450 |