Vulnerabilities > Microfocus

DATE CVE VULNERABILITY TITLE RISK
2022-11-28 CVE-2022-38753 Improper Authentication vulnerability in Microfocus Netiq Advanced Authentication
This update resolves a multi-factor authentication bypass attack
network
low complexity
microfocus CWE-287
6.3
2022-11-21 CVE-2022-38755 Unspecified vulnerability in Microfocus Filr
A vulnerability has been identified in Micro Focus Filr in versions prior to 4.3.1.1.
network
low complexity
microfocus
5.3
2022-05-12 CVE-2021-22531 Cross-site Scripting vulnerability in Microfocus Access Manager 4.5/5.0
A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability.
network
microfocus CWE-79
4.3
2022-05-02 CVE-2022-26325 Cross-site Scripting vulnerability in Microfocus Netiq Access Manager
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2
network
microfocus CWE-79
4.3
2022-05-02 CVE-2022-26326 Open Redirect vulnerability in Microfocus Netiq Access Manager
Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2
5.8
2022-04-11 CVE-2021-38125 Unspecified vulnerability in Microfocus Operations Bridge 2021.05/2021.08
Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08.
network
microfocus
6.8
2022-02-04 CVE-2021-38130 Exposure of Resource to Wrong Sphere vulnerability in Microfocus Voltage Securemail
A potential Information leakage vulnerability has been identified in versions of Micro Focus Voltage SecureMail Mail Relay prior to 7.3.0.1.
network
low complexity
microfocus CWE-668
4.0
2022-01-25 CVE-2021-38129 Unspecified vulnerability in Microfocus Operations Agent
Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and including 12.21.
local
low complexity
microfocus
2.1
2022-01-14 CVE-2021-38126 Cross-site Scripting vulnerability in Microfocus Arcsight Enterprise Security Manager 7.4/7.5
Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x.
network
microfocus CWE-79
4.3
2022-01-14 CVE-2021-38127 Cross-site Scripting vulnerability in Microfocus Arcsight Enterprise Security Manager 7.4/7.5
Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x.
network
microfocus CWE-79
4.3