Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-12 CVE-2024-28990 Use of Hard-coded Credentials vulnerability in Solarwinds Access Rights Manager
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability.
network
low complexity
solarwinds CWE-798
critical
9.8
2024-09-12 CVE-2024-28991 Unspecified vulnerability in Solarwinds Access Rights Manager
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability.
network
low complexity
solarwinds
8.8
2024-09-12 CVE-2021-22503 Cross-site Scripting vulnerability in Microfocus Edirectory
Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.
network
low complexity
microfocus CWE-79
6.1
2024-09-12 CVE-2021-22518 Information Exposure Through Log Files vulnerability in Opentext Identity Manager Azuread Driver
A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file.
local
low complexity
opentext CWE-532
5.5
2024-09-12 CVE-2021-22532 Allocation of Resources Without Limits or Throttling vulnerability in Microfocus Edirectory
Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.
network
low complexity
microfocus CWE-770
7.5
2024-09-12 CVE-2021-22533 Information Exposure Through Log Files vulnerability in Microfocus Edirectory
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.
network
low complexity
microfocus CWE-532
critical
9.1
2024-09-12 CVE-2021-38131 Cross-site Scripting vulnerability in Microfocus Edirectory
Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.
network
low complexity
microfocus CWE-79
6.1
2024-09-12 CVE-2021-38132 Server-Side Request Forgery (SSRF) vulnerability in Microfocus Edirectory
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory.
network
low complexity
microfocus CWE-918
critical
9.8
2024-09-12 CVE-2021-38133 Weak Password Requirements vulnerability in Microfocus Edirectory
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory.
network
low complexity
microfocus CWE-521
6.5
2024-09-12 CVE-2022-26322 Information Exposure Through Log Files vulnerability in Netiq Identity Manager Rest Driver
Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver.
network
low complexity
netiq CWE-532
7.5