Vulnerabilities > Microfocus

DATE CVE VULNERABILITY TITLE RISK
2019-06-03 CVE-2019-11646 Unspecified vulnerability in Microfocus Service Manager
Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61.
network
low complexity
microfocus
8.8
2019-05-09 CVE-2016-1600 Information Exposure vulnerability in Microfocus Identity Manager
The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.
network
low complexity
microfocus CWE-200
7.5
2019-05-02 CVE-2019-3490 Cross-site Scripting vulnerability in Microfocus Open Enterprise Server 2015.1/2018.0/2018.1
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link.
network
low complexity
microfocus CWE-79
6.1
2019-04-29 CVE-2019-3493 Unspecified vulnerability in Microfocus Network Automation and Network Operations Management
A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions.
network
low complexity
microfocus
8.8
2019-04-01 CVE-2019-3489 Unrestricted Upload of File with Dangerous Type vulnerability in Microfocus Content Manager
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method.
network
low complexity
microfocus CWE-434
7.5
2019-03-27 CVE-2018-19644 Cross-site Scripting vulnerability in Microfocus Solutions Business Manager
Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
network
low complexity
microfocus CWE-79
6.1
2019-03-27 CVE-2018-19643 Information Exposure vulnerability in Microfocus Solutions Business Manager
Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
network
low complexity
microfocus CWE-200
7.5
2019-03-27 CVE-2018-19642 Improper Input Validation vulnerability in Microfocus Solutions Business Manager
Denial of service issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
network
low complexity
microfocus CWE-20
7.5
2019-03-27 CVE-2018-19641 Code Injection vulnerability in Microfocus Solutions Business Manager
Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
network
low complexity
microfocus CWE-94
critical
9.8
2019-03-25 CVE-2019-3476 Unspecified vulnerability in Microfocus Data Protector 10.03
Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.
network
low complexity
microfocus
critical
9.8