Loading...
Loading...
This HotStuff specifies the SPR information for CVEs fixed between Nov 2024 and Oct 2025 across a set of NonStop products/modules, including NSJ, Java Middleware, Webserver, Python, and NonStop Manageability Products. The fix SPR identifier indicates the SPR where the fix for the CVE was first introduced.In this HotStuff, compared to the CVEs and fixes published in May 2025, only the Python 3.x (T0993) and Console CLIM Utilities (T0697) products have new CVEs and fix SPRs, and all the other products' CVE and fix SPR lists are the same as the previous CVEs published in May 2025.Please note that at the time of publishing this advisory, there may be other open CVEs against these products. HPE will publish similar HotStuff at regular intervals after the fixes for additional applicable CVEs are available.Common Vulnerabilities and Exposures (CVE) lists publicly disclosed information security vulnerabilities and exposures. The NonStop development group analyzes the CVEs reported against the products/modules used in the products released to customers. If it is found that the released product is vulnerable, corrective action is taken to release a new version of the product.This advisory lists all the applicable CVEs and fixes information against various products.In some cases, even though the CVSS3.X Base Score is extremely high, our assessment indicates that it is challenging to get exposed to the CVE under normal circumstances and would require special privileged access or uncontrolled access to NonStop system components and products to expose a particular CVE. Hence, neither the special time critical security advisory (HS for specific CVE) nor the fix was released, and they are fixed as part of the routine update to the products. Also, as part of the routine product update, low- and medium-score CVEs are also fixed.For detailed information on these vulnerabilities, see the National Vulnerability Database:https://nvd.nist.gov/vuln/detail/CVE-xxxx-xxxxFor additional and more detailed information on CVSS, see the Forum for Incident Response and Security Teams (FIRST) documents available athttps://www.first.org/cvss.The CVSS guide describes the scoring system in detail. Base scores range from 0 (lowest intrinsic vulnerability) to 10 (highest intrinsic vulnerability).
IMPACTED CVEs and FIX INFORMATION:Modular NSJ - 64 BIT - NSJ 11 - T3066L11Modular NSJ - 64 BIT - NSJ 17 - T3066L17CVECVSS3 Base ScoreFixed in VersionVersion Present in RVUCVE-2025-273638.1T3066L17^AAHNoneCVE-2025-215024.8T3066L17^AAHNoneCVE-2024-212103.7T3066L17^AAHNoneCVE-2024-211404.8T3066L17^AAHNoneCVE-2024-211477.4T3066L17^AAHNoneCVE-2023-219675.9T3066L17^AAHNoneCVE-2023-219683.7T3066L17^AAHNoneCVE-2023-219373.7T3066L17^AAHNoneCVE-2023-219307.4T3066L17^AAHNoneCVE-2023-219383.7T3066L17^AAHNoneCVE-2023-219395.3T3066L17^AAHNoneCVE-2023-219545.9T3066L17^AAHNoneCVE-2023-397425.5T3066L17^AAHNoneCVE-2022-285065.5T3066L17^AAHNoneSome SPRs for T3066 L11 have been moved to obsolete status by September 2025. Hence, customers are advised to upgrade NSJ to T3066 L17.Also, NSJ 8 has been moved to obsolete status by September 2025; hence, customers are advised to upgrade from NSJ 8 to NSJ 17.NonStop HTTP Server - T1144L24CVECVSS3 Base ScoreFixed In VersionFix Present in RVUCVE-2022-227219.1T1144L24^AAJNoneCVE-2022-227209.8T1144L24^AAJNoneCVE-2021-442248.2T1144L24^AAJNoneCVE-2022-227197.5T1144L24^AAJNoneCVE-2022-286145.3T1144L24^AAJNoneCVE-2022-305567.5T1144L24^AAJNoneCVE-2022-286159.1T1144L24^AAJNoneCVE-2022-318139.8T1144L24^AAJNoneCVE-2022-263777.5T1144L24^AAJNoneCVE-2022-239439.8T1144L24^AAJNoneCVE-2024-384749.8T1144L24^AAJNoneCVE-2024-384759.1T1144L24^AAJNoneCVE-2024-384769.8T1144L24^AAJNoneCVE-2024-384777.5T1144L24^AAJNoneCVE-2024-395737.5T1144L24^AAJNoneCVE-2023-444877.5T1144L24^AAJNoneCVE-2024-273167.5T1144L24^AAJNoneCVE-2024-247956.3T1144L24^AAJNoneCVE-2023-387097.3T1144L24^AAJNoneCVE-2023-458025.9T1144L24^AAJNoneIn Memory Cache - T1300L01CVECVSS3 Base ScoreFixed in VersionFix Present in RVUCVE-2024-517414.4T1300L01^AANNoneCVE-2023-451453.6T1300L01^AANNoneCVE-2023-410568.1T1300L01^AANNoneCVE-2024-312285.5T1300L01^AANNoneCVE-2024-312274.4T1300L01^AANNoneCVE-2024-314497T1300L01^AANNoneNSASJ - T0950L17CVECVSS3 Base ScoreFixed In VersionFix Present in RVUCVE-2019-149006.5T0950L17^ABBIndependent ProductCVE-2021-35975.9T0950L17^ABBIndependent ProductCVE-2020-106886.1T0950L17^ABBIndependent ProductCVE-2020-106874.8T0950L17^ABBIndependent ProductCVE-2023-11087.5T0950L17^ABBIndependent ProductCVE-2020-107057.5T0950L17^ABBIndependent ProductCVE-2021-36907.5T0950L17^ABBIndependent ProductCVE-2021-36295.9T0950L17^ABBIndependent ProductCVE-2019-101748.8T0950L17^ABBIndependent ProductCVE-2019-102129.8T0950L17^ABBIndependent ProductCVE-2020-107196.5T0950L17^ABBIndependent ProductPYTHON 3.X - T0993L01CVECVSS3 Base ScoreFixed in VersionFix Present in RVUCVE-2024-92877.8T0993L01^AAINoneCVE-2024-62327.5T0993L01^AAINoneCVE-2024-3219Not AvailableT0993L01^AAINoneCVE-2024-03977.4T0993L01^AAINoneCVE-2023-57525.5T0993L01^AAINoneCVE-2018-202257.8T0993L01^AAINoneCVE-2022-408975.9T0993L01^AAINoneCVE-2025-81947.5T0993L01^AALNoneCVE-2025-0938Not AvailableT0993L01^AALNoneCVE-2024-92877.8T0993L01^AALNoneCVE-2024-127185.3T0993L01^AALNoneCVE-2024-122547.5T0993L01^AALNoneCVE-2022-12718.8T0993L01^AALNoneCVE-2015-2328Not AvailableT0993L01^AALNoneCVE-2017-60047.5T0993L01^AALNoneCVE-2015-32177.5T0993L01^AALNoneCVE-2015-23265.5T0993L01^AALNoneCVE-2016-31919.8T0993L01^AALNoneCVE-2015-23257.8T0993L01^AALNoneCVE-2014-97697.3T0993L01^AALNoneCVE-2014-8964Not AvailableT0993L01^AALNoneNSE Installer - Windows - T0895V02CVECVSS3 Base ScoreFixed in VersionFix Present in RVUCVE-2025-215024.8T0895V02^AAUIndependent ProductCVE-2024-81845.9T0895V02^AAUIndependent ProductCVE-2024-67633.7T0895V02^AAUIndependent ProductCVE-2023-219675.9T0895V02^AAUIndependent ProductCVE-2023-219545.9T0895V02^AAUIndependent ProductCVE-2023-219395.3T0895V02^AAUIndependent ProductCVE-2024-212083.7T0895V02^AAUIndependent ProductCVE-2024-211477.4T0895V02^AAUIndependent ProductCVE-2024-211404.8T0895V02^AAUIndependent ProductCVE-2023-219373.7T0895V02^AAUIndependent ProductCVE-2023-219307.4T0895V02^AAUIndependent ProductCVE-2024-212103.7T0895V02^AAUIndependent ProductCVE-2023-219383.7T0895V02^AAUIndependent ProductConsole CLIM Utilities - T0697H01CVECVSS3 Base ScoreFixed in VersionFix Present in RVUCVE-2025-327284.3T0697H01^AAUIndependent Product
Please check for any superseding SPR, there could be a newer SPR available than SPR mentioned above. Please refer to the appropriate softdoc(s) for detailed SPR information, including installation instructions, superseded SPRs, and requisite SPR lists.
Operating Systems Affected:NonStop OS L15.02-L23.08, NonStop OS L24.08, NonStop OS L25.02, Nonstop OS L25.09
Click on a version to see all relevant bugs
Hewlett Packard Enterprise Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.