Vulnerabilities > Microfocus

DATE CVE VULNERABILITY TITLE RISK
2020-10-22 CVE-2020-11853 Arbitrary code execution vulnerability affecting multiple Micro Focus products.
network
low complexity
microfocus hp
8.8
2020-09-22 CVE-2020-11856 Missing Authentication for Critical Function vulnerability in Microfocus Operation Bridge Reporter
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
network
low complexity
microfocus CWE-306
critical
9.8
2020-09-22 CVE-2020-11857 Use of Hard-coded Credentials vulnerability in Microfocus Operation Bridge Reporter
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
network
low complexity
microfocus CWE-798
critical
9.8
2020-09-22 CVE-2020-11855 Incorrect Permission Assignment for Critical Resource vulnerability in Microfocus Operation Bridge Reporter
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
local
low complexity
microfocus CWE-732
7.8
2020-09-18 CVE-2020-11861 Unspecified vulnerability in Microfocus Operations Agent
Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11.
local
low complexity
microfocus
7.8
2020-08-19 CVE-2020-11848 Unspecified vulnerability in Microfocus Arcsight Management Center
Denial of service vulnerability on Micro Focus ArcSight Management Center.
network
low complexity
microfocus
7.5
2020-08-07 CVE-2020-11852 OS Command Injection vulnerability in Microfocus Secure Messaging Gateway 471
DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG).
network
low complexity
microfocus CWE-78
8.8
2020-07-08 CVE-2020-11849 Unspecified vulnerability in Microfocus Identity Manager
Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager.
network
low complexity
microfocus
critical
9.8
2020-06-16 CVE-2020-9522 Cross-site Scripting vulnerability in Microfocus Arcsight Enterprise Security Manager Express 7.0.0/7.2/7.2.1
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 .
network
low complexity
microfocus CWE-79
6.1
2020-06-16 CVE-2020-11841 Unspecified vulnerability in Microfocus Arcsight Management Center
Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4.
network
low complexity
microfocus
4.3