Vulnerabilities > Microfocus
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-26 | CVE-2020-9521 | SQL Injection vulnerability in Microfocus Service Manager Automation An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. | 8.8 |
2020-03-25 | CVE-2020-9520 | Cross-site Scripting vulnerability in Microfocus Vibe 4.0.2 A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. | 5.4 |
2020-03-16 | CVE-2020-9518 | Unspecified vulnerability in Microfocus Service Manager Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. | 5.3 |
2020-03-16 | CVE-2020-9519 | Unspecified vulnerability in Microfocus Service Manager HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. | 5.3 |
2020-03-09 | CVE-2020-9517 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Microfocus Service Manager 9.50/9.60 There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. | 5.4 |
2019-12-17 | CVE-2019-11657 | Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Arcsight Logger 6.61 Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. | 8.8 |
2019-12-11 | CVE-2019-17087 | Unspecified vulnerability in Microfocus Acutoweb Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. | 7.5 |
2019-11-18 | CVE-2019-17085 | XXE vulnerability in Microfocus Operations Agent XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. | 6.5 |
2019-10-22 | CVE-2019-11674 | Improper Certificate Validation vulnerability in Microfocus Netiq Self Service Password Reset Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. | 5.9 |
2019-10-02 | CVE-2019-11651 | Cross-site Scripting vulnerability in Microfocus Enterprise Developer and Enterprise Server Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. | 6.1 |