Vulnerabilities > Microfocus

DATE CVE VULNERABILITY TITLE RISK
2019-08-14 CVE-2019-11652 Unspecified vulnerability in Microfocus Netiq Self Service Password Reset
A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6.
network
low complexity
microfocus
critical
9.8
2019-08-07 CVE-2019-11653 Unspecified vulnerability in Microfocus Content Manager 9.1.0/9.2.0/9.3.0
Remote Access Control Bypass in Micro Focus Content Manager.
network
low complexity
microfocus
5.4
2019-07-10 CVE-2019-11650 Unspecified vulnerability in Microfocus Netiq Advanced Authentication
A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0.
network
high complexity
microfocus
5.9
2019-06-24 CVE-2019-11647 Cross-site Scripting vulnerability in Microfocus Netiq Self Service Password Reset
A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4.
network
low complexity
microfocus CWE-79
6.1
2019-06-19 CVE-2019-11649 Cross-site Scripting vulnerability in Microfocus Fortify Software Security Center 17.20/18.10/18.20
Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center.
network
low complexity
microfocus CWE-79
5.4
2019-06-07 CVE-2019-3477 Open Redirect vulnerability in Microfocus Solutions Business Manager
Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.
network
low complexity
microfocus CWE-601
6.1
2019-06-03 CVE-2019-11646 Unspecified vulnerability in Microfocus Service Manager
Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61.
network
low complexity
microfocus
8.8
2019-05-09 CVE-2016-1600 Information Exposure vulnerability in Microfocus Identity Manager
The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.
network
low complexity
microfocus CWE-200
7.5
2019-05-02 CVE-2019-3490 Cross-site Scripting vulnerability in Microfocus Open Enterprise Server 2015.1/2018.0/2018.1
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link.
network
low complexity
microfocus CWE-79
6.1
2019-04-29 CVE-2019-3493 Unspecified vulnerability in Microfocus Network Automation and Network Operations Management
A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions.
network
low complexity
microfocus
8.8