Executive brief
HPE's Analytics and Location Engine (ALE) API is used for network analytics and location services. An unauthenticated attacker can send specially crafted requests to extract sensitive information, including password hashes, which could be leveraged to compromise user accounts and systems.
Technical details
The vulnerability is an information disclosure issue in the ALE API that accepts unauthenticated requests with specially crafted input to specific endpoints. An attacker can retrieve sensitive data including password hashes without authentication. The vulnerability requires network access but no user interaction or authentication.
Affected products
- HPE Analytics and Location Engine
Timeline
- 2026-09-22: disclosed