microfocus CVE Vulnerabilities & Metrics

Focus on microfocus vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About microfocus Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with microfocus. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total microfocus CVEs: 236
Earliest CVE date: 02 Jun 2001, 04:00 UTC
Latest CVE date: 08 Nov 2024, 18:15 UTC

Latest CVE reference: CVE-2024-9841

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 36

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 157.14%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 157.14%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical microfocus CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.34

Max CVSS: 10.0

Critical CVEs (≥9): 13

CVSS Range vs. Count

Range Count
0.0-3.9 78
4.0-6.9 126
7.0-8.9 34
9.0-10.0 13

CVSS Distribution Chart

Top 5 Highest CVSS microfocus CVEs

These are the five CVEs with the highest CVSS scores for microfocus, sorted by severity first and recency.

All CVEs for microfocus

CVE-2024-9841 microfocus vulnerability CVSS: 0 08 Nov 2024, 18:15 UTC

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

CVE-2020-11859 microfocus vulnerability CVSS: 0 06 Nov 2024, 14:15 UTC

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

CVE-2024-4692 microfocus vulnerability CVSS: 0 16 Oct 2024, 17:15 UTC

Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate Service Virtualization server names. This issue affects OpenText Application Automation Tools: 24.1.0 and below.

CVE-2024-4690 microfocus vulnerability CVSS: 0 16 Oct 2024, 17:15 UTC

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

CVE-2024-4211 microfocus vulnerability CVSS: 0 16 Oct 2024, 17:15 UTC

Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate ALM server names, usernames and client IDs configured to be used with ALM servers. This issue affects OpenText Application Automation Tools: 24.1.0 and below.

CVE-2024-4189 microfocus vulnerability CVSS: 0 16 Oct 2024, 17:15 UTC

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

CVE-2024-4184 microfocus vulnerability CVSS: 0 16 Oct 2024, 17:15 UTC

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

CVE-2021-38133 microfocus vulnerability CVSS: 0 12 Sep 2024, 13:15 UTC

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

CVE-2021-38132 microfocus vulnerability CVSS: 0 12 Sep 2024, 13:15 UTC

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

CVE-2021-38131 microfocus vulnerability CVSS: 0 12 Sep 2024, 13:15 UTC

Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

CVE-2021-22533 microfocus vulnerability CVSS: 0 12 Sep 2024, 13:15 UTC

Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

CVE-2021-22532 microfocus vulnerability CVSS: 0 12 Sep 2024, 13:15 UTC

Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.

CVE-2021-22503 microfocus vulnerability CVSS: 0 12 Sep 2024, 13:15 UTC

Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

CVE-2024-4556 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects NetIQ Access Manager before 5.0.4 and before 5.1.

CVE-2024-4555 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1

CVE-2024-4554 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects NetIQ Access Manager before 5.0.4.1 and 5.1.

CVE-2021-38122 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1

CVE-2021-38121 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices.  This issue affects NetIQ Advance Authentication versions before 6.3.5.1

CVE-2021-38120 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.

CVE-2021-22530 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1

CVE-2021-22529 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1

CVE-2021-22509 microfocus vulnerability CVSS: 0 28 Aug 2024, 07:15 UTC

A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1

CVE-2020-11847 microfocus vulnerability CVSS: 0 21 Aug 2024, 14:15 UTC

SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.

CVE-2020-11846 microfocus vulnerability CVSS: 0 21 Aug 2024, 14:15 UTC

A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1.

CVE-2020-11850 microfocus vulnerability CVSS: 0 21 Aug 2024, 13:15 UTC

Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Password Reset before 4.5.0.2 and 4.4.0.6

CVE-2024-4429 microfocus vulnerability CVSS: 0 28 May 2024, 15:15 UTC

Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.

CVE-2024-3969 microfocus vulnerability CVSS: 0 28 May 2024, 15:15 UTC

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload

CVE-2024-3970 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

CVE-2024-3968 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.

CVE-2024-3967 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.

CVE-2024-3488 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

CVE-2024-3487 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.

CVE-2024-3486 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.

CVE-2024-3485 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

CVE-2024-3484 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.

CVE-2024-3483 microfocus vulnerability CVSS: 0 15 May 2024, 17:15 UTC

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

CVE-2024-0622 microfocus vulnerability CVSS: 0 15 Feb 2024, 21:15 UTC

Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platforms. The vulnerability could allow local privilege escalation. 

CVE-2020-25835 microfocus vulnerability CVSS: 0 09 Dec 2023, 02:15 UTC

A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited resulting in stored Cross-Site Scripting (XSS).

CVE-2023-32268 microfocus vulnerability CVSS: 0 06 Dec 2023, 14:15 UTC

Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.

CVE-2023-5913 microfocus vulnerability CVSS: 0 08 Nov 2023, 17:15 UTC

Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1.

CVE-2023-4964 microfocus vulnerability CVSS: 0 30 Oct 2023, 15:15 UTC

Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset Management X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11. The vulnerability could allow attackers to redirect a user to malicious websites.

CVE-2023-4501 microfocus vulnerability CVSS: 0 12 Sep 2023, 19:15 UTC

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows an attacker with access to the product to impersonate any user. Mitigations: The issue is corrected in the upcoming patch update for each affected product. Product overlays and workaround instructions are available through OpenText Support. The vulnerable configurations are believed to be uncommon. Administrators can test for the vulnerability in their installations by attempting to sign on to a Visual COBOL or Enterprise Server component such as ESCWA using a valid username and incorrect password.

CVE-2023-32267 microfocus vulnerability CVSS: 0 11 Aug 2023, 14:15 UTC

A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited.

CVE-2023-32265 microfocus vulnerability CVSS: 0 20 Jul 2023, 14:15 UTC

A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this vulnerability. As described in the hardening guide in the product documentation, other mitigations including restricting network access to ESCWA and restricting users’ permissions in the Micro Focus Directory Server also reduce the exposure to this issue. Given the right conditions this vulnerability could be exploited to expose a service account password. The account corresponding to the exposed credentials usually has limited privileges and, in many cases would only be useful for extracting details of other user accounts and similar information.

CVE-2023-32263 microfocus vulnerability CVSS: 0 19 Jul 2023, 16:15 UTC

A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability only applies when the Jenkins plugin is configured to use login certificate credentials. https://www.jenkins.io/security/advisory/2023-06-14/

CVE-2023-32262 microfocus vulnerability CVSS: 0 19 Jul 2023, 16:15 UTC

A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Item/Configure permission to access and capture credentials they are not entitled to. See the following Jenkins security advisory for details: * https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/

CVE-2023-32261 microfocus vulnerability CVSS: 0 19 Jul 2023, 16:15 UTC

A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. See the following Jenkins security advisory for details: * https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/

CVE-2023-24470 microfocus vulnerability CVSS: 0 13 Jun 2023, 23:15 UTC

Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.

CVE-2023-24469 microfocus vulnerability CVSS: 0 13 Jun 2023, 22:15 UTC

Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0

CVE-2023-24468 microfocus vulnerability CVSS: 0 15 Mar 2023, 23:15 UTC

Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2

CVE-2022-38757 microfocus vulnerability CVSS: 0 23 Dec 2022, 16:15 UTC

A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in the ZENworks zone but which are outside the scope of the administrator. This vulnerability does not result in the administrators gaining additional rights on the managed devices, either in the scope or outside the scope of the administrator.

CVE-2022-38756 microfocus vulnerability CVSS: 0 16 Dec 2022, 23:15 UTC

A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.

CVE-2022-38754 microfocus vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the Operations Bridge Manager capability is deployed. A potential vulnerability has been identified in Micro Focus Operations Bridge Manager (OBM). The vulnerability could be exploited by a malicious authenticated OBM user to run Java Scripts in the browser context of another OBM user. This issue affects: Micro Focus Micro Focus Operations Bridge Manager versions prior to 2022.11. Micro Focus Micro Focus Operations Bridge- Containerized versions prior to 2022.11.

CVE-2022-38753 microfocus vulnerability CVSS: 0 28 Nov 2022, 22:15 UTC

This update resolves a multi-factor authentication bypass attack

CVE-2022-38755 microfocus vulnerability CVSS: 0 21 Nov 2022, 17:15 UTC

A vulnerability has been identified in Micro Focus Filr in versions prior to 4.3.1.1. The vulnerability could be exploited to allow a remote unauthenticated attacker to enumerate valid users of the system. Remote unauthenticated user enumeration. This issue affects: Micro Focus Filr versions prior to 4.3.1.1.

CVE-2022-26331 microfocus vulnerability CVSS: 0 31 Aug 2022, 16:15 UTC

Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2 version and prior versions.

CVE-2022-26330 microfocus vulnerability CVSS: 0 31 Aug 2022, 16:15 UTC

Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2 version and prior versions.

CVE-2021-22531 microfocus vulnerability CVSS: 4.3 12 May 2022, 19:15 UTC

A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0

CVE-2022-26326 microfocus vulnerability CVSS: 5.8 02 May 2022, 19:15 UTC

Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2

CVE-2022-26325 microfocus vulnerability CVSS: 4.3 02 May 2022, 19:15 UTC

Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2

CVE-2021-38125 microfocus vulnerability CVSS: 6.8 11 Apr 2022, 20:15 UTC

Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be exploited to unauthenticated remote code execution.

CVE-2021-38129 microfocus vulnerability CVSS: 2.1 25 Jan 2022, 20:15 UTC

Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and including 12.21. The vulnerability could be exploited by a non-privileged local user to access system monitoring data collected by Operations Agent.

CVE-2021-38127 microfocus vulnerability CVSS: 4.3 14 Jan 2022, 20:15 UTC

Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).

CVE-2021-38126 microfocus vulnerability CVSS: 4.3 14 Jan 2022, 20:15 UTC

Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).

CVE-2021-38124 microfocus vulnerability CVSS: 7.5 28 Sep 2021, 14:15 UTC

Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution.

CVE-2021-22535 microfocus vulnerability CVSS: 2.7 28 Sep 2021, 14:15 UTC

Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.

CVE-2021-22528 microfocus vulnerability CVSS: 3.5 13 Sep 2021, 12:15 UTC

Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

CVE-2021-22527 microfocus vulnerability CVSS: 5.0 13 Sep 2021, 12:15 UTC

Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

CVE-2021-22526 microfocus vulnerability CVSS: 5.8 13 Sep 2021, 12:15 UTC

Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

CVE-2021-22524 microfocus vulnerability CVSS: 4.0 13 Sep 2021, 12:15 UTC

Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

CVE-2021-38123 microfocus vulnerability CVSS: 5.8 07 Sep 2021, 17:15 UTC

Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.

CVE-2021-22525 microfocus vulnerability CVSS: 2.1 02 Sep 2021, 17:15 UTC

This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1

CVE-2021-22517 microfocus vulnerability CVSS: 6.5 05 Aug 2021, 21:15 UTC

A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulnerability affects versions 10.10, 10.20, 10.30, 10.40, 10.50, 10.60, 10.70, 10.80, 10.0 and 10.91. A privileged user may potentially misuse this feature and thus allow unintended and unauthorized access of data.

CVE-2021-22521 microfocus vulnerability CVSS: 7.2 30 Jul 2021, 21:15 UTC

A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.

CVE-2021-22523 microfocus vulnerability CVSS: 6.8 22 Jul 2021, 12:15 UTC

XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.

CVE-2021-22522 microfocus vulnerability CVSS: 6.8 22 Jul 2021, 12:15 UTC

Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Update 1 and earlier versions. The vulnerability could allow disclosure of confidential data.

CVE-2021-22515 microfocus vulnerability CVSS: 4.0 12 Jul 2021, 11:15 UTC

Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1.

CVE-2021-22516 microfocus vulnerability CVSS: 5.0 04 Jun 2021, 13:15 UTC

Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file.

CVE-2021-22519 microfocus vulnerability CVSS: 7.5 28 May 2021, 20:15 UTC

Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), 2018.08(11.51), 2018.11(11.60), 2019.02(11.70), 2019.05(11.80), 2019.08(11.90), 2019.11(11.91), 2020.05(11.92), 2020.10(11.93). The vulnerability could allow remote attackers to execute arbitrary code on affected installations of SiteScope.

CVE-2021-22514 microfocus vulnerability CVSS: 7.5 28 Apr 2021, 12:15 UTC

An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of APM.

CVE-2021-22505 microfocus vulnerability CVSS: 7.5 13 Apr 2021, 14:15 UTC

Escalation of privileges vulnerability in Micro Focus Operations Agent, affects versions 12.0x, 12.10, 12.11, 12.12, 12.14 and 12.15. The vulnerability could be exploited to escalate privileges and execute code under the account of the Operations Agent.

CVE-2021-22497 microfocus vulnerability CVSS: 6.5 12 Apr 2021, 21:15 UTC

Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.

CVE-2021-22513 microfocus vulnerability CVSS: 4.0 08 Apr 2021, 22:15 UTC

Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow access without permission checks.

CVE-2021-22512 microfocus vulnerability CVSS: 4.3 08 Apr 2021, 22:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow form validation without permission checks.

CVE-2021-22511 microfocus vulnerability CVSS: 6.4 08 Apr 2021, 22:15 UTC

Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow unconditionally disabling of SSL/TLS certificates.

CVE-2021-22510 microfocus vulnerability CVSS: 4.3 08 Apr 2021, 22:15 UTC

Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects all version 6.7 and earlier versions.

CVE-2021-22507 microfocus vulnerability CVSS: 7.5 08 Apr 2021, 18:15 UTC

Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access.

CVE-2021-22506 microfocus vulnerability CVSS: 5.0 26 Mar 2021, 14:15 UTC

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

CVE-2020-25840 microfocus vulnerability CVSS: 4.3 26 Mar 2021, 14:15 UTC

Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction.

CVE-2021-22496 microfocus vulnerability CVSS: 5.0 25 Mar 2021, 16:15 UTC

Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.

CVE-2019-18947 microfocus vulnerability CVSS: 2.7 26 Feb 2021, 04:15 UTC

Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.

CVE-2019-18946 microfocus vulnerability CVSS: 3.8 26 Feb 2021, 04:15 UTC

Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.

CVE-2019-18945 microfocus vulnerability CVSS: 5.2 26 Feb 2021, 04:15 UTC

Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability.

CVE-2019-18944 microfocus vulnerability CVSS: 2.3 26 Feb 2021, 04:15 UTC

Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.

CVE-2019-18943 microfocus vulnerability CVSS: 5.2 26 Feb 2021, 04:15 UTC

Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.

CVE-2019-18942 microfocus vulnerability CVSS: 2.3 26 Feb 2021, 04:15 UTC

Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.

CVE-2021-22504 microfocus vulnerability CVSS: 10.0 12 Feb 2021, 20:15 UTC

Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could allow remote attackers to execute arbitrary code on an OBM server.

CVE-2021-22502 microfocus vulnerability CVSS: 10.0 08 Feb 2021, 22:15 UTC

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

CVE-2021-22500 microfocus vulnerability CVSS: 4.3 06 Feb 2021, 02:15 UTC

Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.

CVE-2021-22499 microfocus vulnerability CVSS: 3.5 06 Feb 2021, 01:15 UTC

Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow persistent XSS attack.

CVE-2021-22498 microfocus vulnerability CVSS: 5.5 19 Jan 2021, 16:15 UTC

XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited to allow an XML External Entity Injection.

CVE-2020-25838 microfocus vulnerability CVSS: 4.0 11 Dec 2020, 02:15 UTC

Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x versions. The vulnerability could be exploited to disclose unauthorized sensitive information.

CVE-2020-25839 microfocus vulnerability CVSS: 7.5 20 Nov 2020, 16:15 UTC

NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.

CVE-2020-25832 microfocus vulnerability CVSS: 3.5 17 Nov 2020, 02:15 UTC

Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability could be exploited to perform Reflected XSS attack.

CVE-2020-11851 microfocus vulnerability CVSS: 7.5 17 Nov 2020, 02:15 UTC

Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.

CVE-2020-25834 microfocus vulnerability CVSS: 3.5 17 Nov 2020, 01:15 UTC

Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).

CVE-2020-11860 microfocus vulnerability CVSS: 4.3 17 Nov 2020, 01:15 UTC

Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS)

CVE-2020-25837 microfocus vulnerability CVSS: 4.3 05 Nov 2020, 21:15 UTC

Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.

CVE-2020-11858 microfocus vulnerability CVSS: 4.6 27 Oct 2020, 17:15 UTC

Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Bridge (containerized). The vulneravility affects: 1.) Operation Bridge Manager versions: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) versions: 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. The vulnerability could allow local attackers to execute code with escalated privileges.

CVE-2020-11854 microfocus vulnerability CVSS: 10.0 27 Oct 2020, 17:15 UTC

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

CVE-2020-11853 microfocus vulnerability CVSS: 6.5 22 Oct 2020, 21:15 UTC

Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.

CVE-2020-11856 microfocus vulnerability CVSS: 10.0 22 Sep 2020, 15:15 UTC

Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.

CVE-2020-11857 microfocus vulnerability CVSS: 7.5 22 Sep 2020, 14:15 UTC

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user

CVE-2020-11855 microfocus vulnerability CVSS: 7.2 22 Sep 2020, 14:15 UTC

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with escalated privileges.

CVE-2020-11861 microfocus vulnerability CVSS: 7.2 18 Sep 2020, 21:15 UTC

Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11. The vulnerability could be exploited to escalate the local privileges and gain root access on the system.

CVE-2020-11848 microfocus vulnerability CVSS: 5.0 19 Aug 2020, 15:15 UTC

Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions prior to version 2.9.5. The vulnerability could cause the server to become unavailable, causing a denial of service.

CVE-2020-11852 microfocus vulnerability CVSS: 9.0 07 Aug 2020, 16:15 UTC

DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key information to inject system commands into the call to the DKIM system command.

CVE-2020-11849 microfocus vulnerability CVSS: 7.5 08 Jul 2020, 14:15 UTC

Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an unauthorized access.

CVE-2020-9522 microfocus vulnerability CVSS: 4.3 16 Jun 2020, 14:15 UTC

Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.

CVE-2020-11841 microfocus vulnerability CVSS: 4.0 16 Jun 2020, 14:15 UTC

Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure.

CVE-2020-11840 microfocus vulnerability CVSS: 4.0 16 Jun 2020, 14:15 UTC

Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure.

CVE-2020-11838 microfocus vulnerability CVSS: 3.5 16 Jun 2020, 14:15 UTC

Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.

CVE-2020-11839 microfocus vulnerability CVSS: 4.3 12 Jun 2020, 23:15 UTC

Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.

CVE-2020-11844 microfocus vulnerability CVSS: 7.5 29 May 2020, 22:15 UTC

Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions 2018.05 to 2019.11. - ArcSight Investigate. versions 2.4.0, 3.0.0 and 3.1.0. - ArcSight Transformation Hub. versions 3.0.0, 3.1.0, 3.2.0. - ArcSight Interset. version 6.0.0. - ArcSight ESM (when ArcSight Fusion 1.0 is installed). version 7.2.1. - Service Management Automation (SMA). versions 2018.05 to 2020.02 - Operation Bridge Suite (Containerized). Versions 2018.05 to 2020.02. - Network Operation Management. versions 2017.11 to 2019.11. - Data Center Automation Containerized. versions 2018.05 to 2019.11 - Identity Intelligence. versions 1.1.0 and 1.1.1. The vulnerability could be exploited to provide unauthorized access to the Container Deployment Foundation.

CVE-2020-11845 microfocus vulnerability CVSS: 4.3 19 May 2020, 15:15 UTC

Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers to inject arbitrary web script or HTML.

CVE-2020-9524 microfocus vulnerability CVSS: 3.5 18 May 2020, 14:15 UTC

Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).

CVE-2020-11842 microfocus vulnerability CVSS: 5.0 04 May 2020, 13:15 UTC

Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier than 7.8 Update 1 (7.8.49 or 7.8.0.49). The vulnerability allows an unauthenticated attackers to view information they may not have been authorized to view.

CVE-2020-9523 microfocus vulnerability CVSS: 6.5 17 Apr 2020, 15:15 UTC

Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary site, compromising that account's security.

CVE-2020-9521 microfocus vulnerability CVSS: 6.5 26 Mar 2020, 15:15 UTC

An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead to the product being vulnerable to SQL injection.

CVE-2020-9520 microfocus vulnerability CVSS: 3.5 25 Mar 2020, 21:15 UTC

A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in the security context of the target user’s browser.

CVE-2020-9518 microfocus vulnerability CVSS: 5.0 16 Mar 2020, 14:15 UTC

Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to configuration data.

CVE-2020-9519 microfocus vulnerability CVSS: 5.0 16 Mar 2020, 13:15 UTC

HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow exposure of configuration data.

CVE-2020-9517 microfocus vulnerability CVSS: 4.9 09 Mar 2020, 16:15 UTC

There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress attacks.

CVE-2019-11657 microfocus vulnerability CVSS: 6.8 17 Dec 2019, 23:15 UTC

Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could be exploited to perform CSRF attack.

CVE-2019-17087 microfocus vulnerability CVSS: 5.0 11 Dec 2019, 23:15 UTC

Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and download files from the filesystem of the system running AcuToWeb, with the privileges of the account AcuToWeb is running under.

CVE-2019-17085 microfocus vulnerability CVSS: 4.0 18 Nov 2019, 21:15 UTC

XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Operations Agent.

CVE-2019-11674 microfocus vulnerability CVSS: 4.3 22 Oct 2019, 15:15 UTC

Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.

CVE-2019-11651 microfocus vulnerability CVSS: 4.3 02 Oct 2019, 21:15 UTC

Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. The vulnerability could be exploited to redirect a user to a malicious page or forge certain types of web requests.

CVE-2019-11664 microfocus vulnerability CVSS: 4.0 18 Sep 2019, 22:15 UTC

Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

CVE-2019-11663 microfocus vulnerability CVSS: 4.0 18 Sep 2019, 22:15 UTC

Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

CVE-2019-11662 microfocus vulnerability CVSS: 4.0 18 Sep 2019, 22:15 UTC

Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited in some special cases to allow information exposure through an error message.

CVE-2019-11661 microfocus vulnerability CVSS: 6.5 18 Sep 2019, 22:15 UTC

Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited to allow unauthorized access and modification of data.

CVE-2019-11665 microfocus vulnerability CVSS: 5.0 17 Sep 2019, 20:15 UTC

Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

CVE-2019-11666 microfocus vulnerability CVSS: 6.8 17 Sep 2019, 19:15 UTC

Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data.

CVE-2019-11667 microfocus vulnerability CVSS: 5.0 17 Sep 2019, 18:15 UTC

Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to private data.

CVE-2019-11660 microfocus vulnerability CVSS: 7.2 13 Sep 2019, 18:15 UTC

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

CVE-2019-11669 microfocus vulnerability CVSS: 5.0 10 Sep 2019, 21:15 UTC

Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62. This vulnerability could be exploited to allow unauthorized modification of data.

CVE-2019-11668 microfocus vulnerability CVSS: 5.0 10 Sep 2019, 21:15 UTC

HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Server, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Service 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62.

CVE-2019-11658 microfocus vulnerability CVSS: 4.0 30 Aug 2019, 09:15 UTC

Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access when the system is in an undisclosed abnormal state.

CVE-2019-11654 microfocus vulnerability CVSS: 5.0 23 Aug 2019, 18:15 UTC

Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files.

CVE-2019-11653 microfocus vulnerability CVSS: 5.5 07 Aug 2019, 17:15 UTC

Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploited to manipulate data stored during another user’s CheckIn request.

CVE-2019-11650 microfocus vulnerability CVSS: 4.3 10 Jul 2019, 19:15 UTC

A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0.

CVE-2019-11647 microfocus vulnerability CVSS: 4.3 24 Jun 2019, 16:15 UTC

A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.

CVE-2019-11649 microfocus vulnerability CVSS: 3.5 19 Jun 2019, 17:15 UTC

Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to execute JavaScript code in user’s browser. The vulnerability could be exploited to execute JavaScript code in user’s browser.

CVE-2019-3477 microfocus vulnerability CVSS: 5.8 07 Jun 2019, 17:29 UTC

Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.

CVE-2019-11646 microfocus vulnerability CVSS: 9.0 03 Jun 2019, 17:29 UTC

Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61. This vulnerability could allow Remote unauthorized command execution and unauthorized disclosure of information.

CVE-2016-1600 microfocus vulnerability CVSS: 5.0 09 May 2019, 21:29 UTC

The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.

CVE-2019-3490 microfocus vulnerability CVSS: 4.3 02 May 2019, 17:29 UTC

A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.

CVE-2019-3493 microfocus vulnerability CVSS: 6.5 29 Apr 2019, 16:29 UTC

A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions. The vulnerability could be remotely exploited to Remote Code Execution.

CVE-2019-3489 microfocus vulnerability CVSS: 5.0 01 Apr 2019, 20:29 UTC

An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the Content Manager server.

CVE-2018-19644 microfocus vulnerability CVSS: 4.3 27 Mar 2019, 18:29 UTC

Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

CVE-2018-19643 microfocus vulnerability CVSS: 5.0 27 Mar 2019, 18:29 UTC

Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

CVE-2018-19642 microfocus vulnerability CVSS: 5.0 27 Mar 2019, 17:29 UTC

Denial of service issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

CVE-2018-19641 microfocus vulnerability CVSS: 7.5 27 Mar 2019, 17:29 UTC

Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

CVE-2019-3476 microfocus vulnerability CVSS: 7.5 25 Mar 2019, 17:29 UTC

Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.

CVE-2016-9166 microfocus vulnerability CVSS: 5.0 21 Mar 2019, 15:59 UTC

NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.

CVE-2019-3475 microfocus vulnerability CVSS: 7.2 20 Feb 2019, 22:29 UTC

A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

CVE-2019-3474 microfocus vulnerability CVSS: 4.0 20 Feb 2019, 22:29 UTC

A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

CVE-2018-19645 microfocus vulnerability CVSS: 7.5 12 Feb 2019, 20:29 UTC

An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

CVE-2019-5736 microfocus vulnerability CVSS: 9.3 11 Feb 2019, 19:29 UTC

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

CVE-2018-7691 microfocus vulnerability CVSS: 4.0 13 Dec 2018, 14:29 UTC

A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access

CVE-2018-7690 microfocus vulnerability CVSS: 4.0 13 Dec 2018, 14:29 UTC

A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access

CVE-2018-17952 microfocus vulnerability CVSS: 4.3 12 Dec 2018, 14:29 UTC

Cross site scripting vulnerability in eDirectory prior to 9.1 SP2

CVE-2018-17950 microfocus vulnerability CVSS: 5.0 12 Dec 2018, 14:29 UTC

Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2

CVE-2018-17949 microfocus vulnerability CVSS: 4.3 12 Dec 2018, 14:29 UTC

Cross site scripting vulnerability in iManager prior to 3.1 SP2.

CVE-2009-5153 microfocus vulnerability CVSS: 7.5 21 Nov 2018, 15:29 UTC

In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote unauthenticated attackers to execute code, because a length field was incorrectly trusted.

CVE-2018-17948 microfocus vulnerability CVSS: 5.8 20 Nov 2018, 18:29 UTC

An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.

CVE-2018-12480 microfocus vulnerability CVSS: 4.3 15 Nov 2018, 13:29 UTC

Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.

CVE-2018-18591 microfocus vulnerability CVSS: 4.0 13 Nov 2018, 13:29 UTC

A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51. The vulnerability could be exploited to release unauthorized disclosure of data.

CVE-2018-18590 microfocus vulnerability CVSS: 5.8 07 Nov 2018, 16:29 UTC

A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge containerized suite versions 2017.11, 2018.02, 2018.05, 2018.08. This vulnerability could allow for information disclosure.

CVE-2018-18589 microfocus vulnerability CVSS: 6.5 23 Oct 2018, 17:29 UTC

A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.

CVE-2018-12469 microfocus vulnerability CVSS: 5.0 12 Oct 2018, 13:29 UTC

Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination.

CVE-2018-6504 microfocus vulnerability CVSS: 6.8 20 Sep 2018, 19:29 UTC

A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Cross-Site Request Forgery (CSRF).

CVE-2018-6499 microfocus vulnerability CVSS: 7.5 30 Aug 2018, 21:29 UTC

Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05, Service Virtualization (SV) with floating licenses using Any version using APLS older than 10.7, Unified Functional Testing (UFT) with floating licenses using Any version using APLS older than 10.7, Network Virtualization (NV) with floating licenses using Any version using APLS older than 10.7 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.

CVE-2018-6498 microfocus vulnerability CVSS: 7.5 30 Aug 2018, 21:29 UTC

Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.

CVE-2018-7692 microfocus vulnerability CVSS: 5.8 09 Aug 2018, 21:29 UTC

Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.

CVE-2018-7686 microfocus vulnerability CVSS: 5.0 09 Aug 2018, 21:29 UTC

Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.

CVE-2018-12468 microfocus vulnerability CVSS: 6.5 01 Aug 2018, 20:29 UTC

A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server. In certain circumstances this could result in remote code execution.

CVE-2018-7682 microfocus vulnerability CVSS: 4.0 22 Jun 2018, 22:29 UTC

Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.

CVE-2018-7683 microfocus vulnerability CVSS: 5.0 21 Jun 2018, 19:29 UTC

Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.

CVE-2018-7681 microfocus vulnerability CVSS: 3.5 21 Jun 2018, 19:29 UTC

Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system.

CVE-2018-7680 microfocus vulnerability CVSS: 4.3 21 Jun 2018, 19:29 UTC

Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.

CVE-2018-7679 microfocus vulnerability CVSS: 7.5 21 Jun 2018, 19:29 UTC

Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.

CVE-2018-6497 microfocus vulnerability CVSS: 6.8 16 Jun 2018, 01:29 UTC

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).

CVE-2018-6496 microfocus vulnerability CVSS: 6.8 16 Jun 2018, 01:29 UTC

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).

CVE-2018-6495 microfocus vulnerability CVSS: 3.5 23 May 2018, 18:29 UTC

Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).

CVE-2018-6494 microfocus vulnerability CVSS: 5.5 22 May 2018, 18:29 UTC

Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.

CVE-2018-7687 microfocus vulnerability CVSS: 4.6 21 May 2018, 20:29 UTC

The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevate privileges via a buffer overflow in ncfsd.sys.

CVE-2018-6491 microfocus vulnerability CVSS: 7.2 24 Apr 2018, 01:29 UTC

Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.

CVE-2018-7675 microfocus vulnerability CVSS: 3.5 07 Mar 2018, 22:29 UTC

In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes the interface to timeout so that it requires the user to re-authenticate. If another user is passing by and decides to login, their credentials are accepted. While The user does not inherit any of the other users privileges, they are able to view the previous screen. In this case it is possible that the user can see another users events or configuration information for whatever view is currently showing.

CVE-2017-9285 microfocus vulnerability CVSS: 7.5 02 Mar 2018, 20:29 UTC

NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.

CVE-2017-7429 microfocus vulnerability CVSS: 6.5 02 Mar 2018, 20:29 UTC

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.

CVE-2018-6489 microfocus vulnerability CVSS: 7.5 22 Feb 2018, 22:29 UTC

XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE)

CVE-2018-6488 microfocus vulnerability CVSS: 7.5 22 Feb 2018, 22:29 UTC

Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution.

CVE-2018-6487 microfocus vulnerability CVSS: 5.0 20 Feb 2018, 21:29 UTC

Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information.

CVE-2017-8993 microfocus vulnerability CVSS: 3.5 15 Feb 2018, 22:29 UTC

A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found.

CVE-2018-6486 microfocus vulnerability CVSS: 7.5 02 Feb 2018, 14:29 UTC

XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.

CVE-2017-14363 microfocus vulnerability CVSS: 3.5 21 Dec 2017, 22:29 UTC

Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).

CVE-2017-14362 microfocus vulnerability CVSS: 6.8 13 Dec 2017, 01:29 UTC

Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Cross-Site Forgery attack.

CVE-2017-14361 microfocus vulnerability CVSS: 5.8 13 Dec 2017, 01:29 UTC

Man-In-The-Middle vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Man-in-the-middle attack.

CVE-2017-14355 microfocus vulnerability CVSS: 7.2 05 Dec 2017, 21:29 UTC

A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability could be exploited locally to allow escalation of privilege.

CVE-2017-9273 microfocus vulnerability CVSS: 5.0 06 Oct 2017, 17:29 UTC

The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes.

CVE-2017-9272 microfocus vulnerability CVSS: 5.0 06 Oct 2017, 17:29 UTC

The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.

CVE-2017-9283 microfocus vulnerability CVSS: 7.5 21 Sep 2017, 22:29 UTC

An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.

CVE-2017-9282 microfocus vulnerability CVSS: 7.5 21 Sep 2017, 22:29 UTC

An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corruption in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.

CVE-2017-9281 microfocus vulnerability CVSS: 5.0 21 Sep 2017, 22:29 UTC

An integer overflow (CWE-190) potentially causing an out-of-bounds read (CWE-125) vulnerability in Micro Focus VisiBroker 8.5 can lead to a denial of service.

CVE-2017-7424 microfocus vulnerability CVSS: 4.0 21 Aug 2017, 15:29 UTC

A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to download arbitrary files from a system running the product, if this component is configured. Note esfadmingui is not enabled by default.

CVE-2017-7423 microfocus vulnerability CVSS: 6.8 21 Aug 2017, 15:29 UTC

A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is configured. This includes creating new privileged credentials, resulting in privilege elevation (CWE-275). Note esfadmingui is not enabled by default.

CVE-2017-7422 microfocus vulnerability CVSS: 3.5 21 Aug 2017, 15:29 UTC

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features, if this component is configured. Note esfadmingui is not enabled by default.

CVE-2017-7421 microfocus vulnerability CVSS: 4.3 21 Aug 2017, 15:29 UTC

Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.

CVE-2017-7420 microfocus vulnerability CVSS: 7.5 21 Aug 2017, 15:29 UTC

An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration information and alter the state of the running product (CWE-275).

CVE-2017-5187 microfocus vulnerability CVSS: 6.8 21 Aug 2017, 15:29 UTC

A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter (CWE-275) configuration information and inject OS commands (CWE-78) via forged requests.

CVE-2017-5185 microfocus vulnerability CVSS: 5.0 30 Mar 2017, 17:59 UTC

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.

CVE-2017-5184 microfocus vulnerability CVSS: 5.0 30 Mar 2017, 17:59 UTC

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).

CVE-2016-5765 microfocus vulnerability CVSS: 4.3 29 Nov 2016, 11:59 UTC

Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal. Applies to MSS 12.3 before 12.3.326 and MSS 12.2 before 12.2.342 and RSG 12.1 before 12.1.362 and RWeb 12.3 before 12.3.312 and RWeb 12.2 before 12.2.342 and RWeb 12.1 before 12.1.362 and ZFE 2.0.1 before 2.0.1.18 and ZFE 2.0.0 before 2.0.0.52 and ZFE 1.4.0 before 1.4.0.14.

CVE-2016-9176 microfocus vulnerability CVSS: 7.5 04 Nov 2016, 00:59 UTC

Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or attackers able to inject arguments to these binaries to execute code.

CVE-2016-5764 microfocus vulnerability CVSS: 6.8 27 Oct 2016, 20:59 UTC

Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (HF 14668). This can only occur if a client connects to a malicious server.

CVE-2016-5228 microfocus vulnerability CVSS: 10.0 03 Jul 2016, 01:59 UTC

Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.4.x before 9.4 HF 12815 allows remote attackers to execute arbitrary code via a long MacroName argument. NOTE: some references mention CVE-2016-5226 but that is not a correct ID for any Rumba vulnerability.

CVE-2016-1606 microfocus vulnerability CVSS: 10.0 03 Jul 2016, 01:59 UTC

Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName property value to ObjectXSNAConfig.ObjectXSNAConfig in iconfig.dll, (2) the CPName property value to ObjectXSNAConfig.ObjectXSNAConfig in iconfig.dll, (3) the PrinterName property value to ProfileEditor.PrintPasteControl in ProfEdit.dll, (4) the Data argument to the WriteRecords function in FTXBIFFLib.AS400FtxBIFF in FtxBIFF.dll, (5) the Serialized property value to NMSECCOMPARAMSLib.SSL3 in NMSecComParams.dll, (6) the UserName property value to NMSECCOMPARAMSLib.FirewallProxy in NMSecComParams.dll, (7) the LUName property value to ProfileEditor.MFSNAControl in ProfEdit.dll, (8) the newVal argument to the Load function in FTPSFTPLib.SFtpSession in FTPSFtp.dll, or (9) a long Host field in the FTP Client.

CVE-2016-1599 microfocus vulnerability CVSS: 4.3 24 Mar 2016, 01:59 UTC

Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2016-1991 microfocus vulnerability CVSS: 6.0 16 Mar 2016, 10:59 UTC

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors.

CVE-2016-1990 microfocus vulnerability CVSS: 4.3 16 Mar 2016, 10:59 UTC

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.

CVE-2015-6030 microfocus vulnerability CVSS: 7.2 04 Nov 2015, 03:59 UTC

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.

CVE-2015-6946 microfocus vulnerability CVSS: 9.3 15 Sep 2015, 18:59 UTC

Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary code via the (1) akey or (2) actserver parameter to the activate_doit function or (3) licfile parameter to the service_startup_doit functionality.

CVE-2015-0795 microfocus vulnerability CVSS: 6.8 18 Jul 2015, 10:59 UTC

Multiple stack-based buffer overflows in the SafeShellExecute method in the NetIQExecObject.NetIQExec.1 ActiveX control in NetIQExec.dll in NetIQ Security Solutions for iSeries 8.1 allow remote attackers to execute arbitrary code via long arguments, aka ZDI-CAN-2699.

CVE-2014-7885 microfocus vulnerability CVSS: 10.0 14 Mar 2015, 01:59 UTC

Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors.

CVE-2014-9412 microfocus vulnerability CVSS: 4.3 23 Dec 2014, 11:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter to roma/jsp/debug/debug.jsp or (2) an arbitrary parameter in a debug.DumpAll action to nps/servlet/webacc, a different issue than CVE-2014-5216.

CVE-2014-5217 microfocus vulnerability CVSS: 6.8 23 Dec 2014, 11:59 UTC

Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via an fw.SetPassword action.

CVE-2014-5216 microfocus vulnerability CVSS: 4.3 23 Dec 2014, 11:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web script or HTML via (1) the location parameter in a dev.Empty action to nps/servlet/webacc, (2) the error parameter to nidp/jsp/x509err.jsp, (3) the lang parameter to sslvpn/applet_agent.jsp, or (4) the secureLoggingServersA parameter to roma/system/cntl, a different issue than CVE-2014-9412.

CVE-2014-5215 microfocus vulnerability CVSS: 4.0 23 Dec 2014, 11:59 UTC

NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated administrators to discover service-account passwords via a request to (1) roma/jsp/volsc/monitoring/dev_services.jsp or (2) roma/jsp/debug/debug.jsp.

CVE-2014-5214 microfocus vulnerability CVSS: 4.0 23 Dec 2014, 11:59 UTC

nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVE-2014-0602 microfocus vulnerability CVSS: 7.5 07 Jul 2014, 11:01 UTC

Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager through 6.5.4 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3460.

CVE-2014-3460 microfocus vulnerability CVSS: 6.8 20 May 2014, 11:13 UTC

Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted pathname.

CVE-2012-0432 microfocus vulnerability CVSS: 10.0 25 Dec 2012, 12:13 UTC

Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.

CVE-2012-0430 microfocus vulnerability CVSS: 6.4 25 Dec 2012, 12:13 UTC

Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors.

CVE-2012-0429 microfocus vulnerability CVSS: 4.0 25 Dec 2012, 12:13 UTC

dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request.

CVE-2012-0428 microfocus vulnerability CVSS: 4.3 25 Dec 2012, 12:13 UTC

Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-5932 microfocus vulnerability CVSS: 10.0 24 Dec 2012, 18:55 UTC

Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute arbitrary Perl code via a crafted application/x-amf request.

CVE-2012-5931 microfocus vulnerability CVSS: 5.5 24 Dec 2012, 18:55 UTC

Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote authenticated users to create or overwrite arbitrary files via directory traversal sequences in a log pathname.

CVE-2012-5930 microfocus vulnerability CVSS: 6.4 24 Dec 2012, 18:55 UTC

The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the passwords of administrative accounts via a crafted application/x-amf request.

CVE-2001-0208 microfocus vulnerability CVSS: 4.6 02 Jun 2001, 04:00 UTC

MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.