Vulnerabilities > Microfocus

DATE CVE VULNERABILITY TITLE RISK
2024-11-08 CVE-2024-9841 Cross-site Scripting vulnerability in Microfocus Arcsight Management Center and Arcsight Platform
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform.
network
low complexity
microfocus CWE-79
6.1
2024-11-06 CVE-2020-11859 Cross-site Scripting vulnerability in Microfocus Imanager
Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3
network
low complexity
microfocus CWE-79
5.4
2024-10-16 CVE-2024-4184 XXE vulnerability in Microfocus Application Automation Tools
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
network
low complexity
microfocus CWE-611
8.0
2024-10-16 CVE-2024-4189 XXE vulnerability in Microfocus Application Automation Tools
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
network
low complexity
microfocus CWE-611
8.0
2024-10-16 CVE-2024-4211 Unspecified vulnerability in Microfocus Application Automation Tools
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools.
network
low complexity
microfocus
2.4
2024-10-16 CVE-2024-4690 XXE vulnerability in Microfocus Application Automation Tools
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
network
low complexity
microfocus CWE-611
8.0
2024-10-16 CVE-2024-4692 Unspecified vulnerability in Microfocus Application Automation Tools
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools.
network
low complexity
microfocus
2.4
2024-09-12 CVE-2021-22503 Cross-site Scripting vulnerability in Microfocus Edirectory
Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.
network
low complexity
microfocus CWE-79
6.1
2024-09-12 CVE-2021-22532 Allocation of Resources Without Limits or Throttling vulnerability in Microfocus Edirectory
Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.
network
low complexity
microfocus CWE-770
7.5
2024-09-12 CVE-2021-22533 Information Exposure Through Log Files vulnerability in Microfocus Edirectory
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.
network
low complexity
microfocus CWE-532
critical
9.1