Vulnerabilities > Microfocus > Enterprise Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-07-20 CVE-2023-32265 Unspecified vulnerability in Microfocus products
A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this vulnerability.
network
low complexity
microfocus
6.5
2020-05-18 CVE-2020-9524 Cross-site Scripting vulnerability in Microfocus Enterprise Developer and Enterprise Server
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8.
network
low complexity
microfocus CWE-79
5.4
2019-10-02 CVE-2019-11651 Cross-site Scripting vulnerability in Microfocus Enterprise Developer and Enterprise Server
Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2.
network
low complexity
microfocus CWE-79
6.1
2017-08-21 CVE-2017-7424 Path Traversal vulnerability in Microfocus Enterprise Developer and Enterprise Server
A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to download arbitrary files from a system running the product, if this component is configured.
network
low complexity
microfocus CWE-22
6.5
2017-08-21 CVE-2017-7422 Cross-site Scripting vulnerability in Microfocus Enterprise Developer and Enterprise Server
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features, if this component is configured.
network
low complexity
microfocus CWE-79
5.4
2017-08-21 CVE-2017-7421 Cross-site Scripting vulnerability in Microfocus products
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.
network
low complexity
microfocus CWE-79
6.1