Vulnerabilities > Microfocus > Imanager
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-06 | CVE-2020-11859 | Cross-site Scripting vulnerability in Microfocus Imanager Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3 | 5.4 |
2024-05-28 | CVE-2024-3969 | XXE vulnerability in Microfocus Imanager 3.2.6 XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. | 9.8 |
2024-05-28 | CVE-2024-4429 | Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Imanager 3.2.6 Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. | 7.4 |
2024-05-15 | CVE-2024-3483 | Deserialization of Untrusted Data vulnerability in Microfocus Imanager Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues. | 9.8 |
2024-05-15 | CVE-2024-3484 | Path Traversal vulnerability in Microfocus Imanager 3.2.6 Path Traversal found in OpenText™ iManager 3.2.6.0200. | 9.8 |
2024-05-15 | CVE-2024-3485 | Server-Side Request Forgery (SSRF) vulnerability in Microfocus Imanager 3.2.6 Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. | 7.5 |
2024-05-15 | CVE-2024-3486 | XXE vulnerability in Microfocus Imanager 3.2.6 XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. | 9.8 |
2024-05-15 | CVE-2024-3487 | Improper Authentication vulnerability in Microfocus Imanager 3.2.6 Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication. | 9.8 |
2024-05-15 | CVE-2024-3488 | Unrestricted Upload of File with Dangerous Type vulnerability in Microfocus Imanager 3.2.6 File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication. | 9.8 |
2024-05-15 | CVE-2024-3967 | Deserialization of Untrusted Data vulnerability in Microfocus Imanager 3.2.6 Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization. | 9.8 |