Vulnerabilities > Microfocus

DATE CVE VULNERABILITY TITLE RISK
2021-04-12 CVE-2021-22497 Improper Authentication vulnerability in Microfocus Netiq Advanced Authentication
Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.
network
low complexity
microfocus CWE-287
7.2
2021-04-08 CVE-2021-22513 Missing Authorization vulnerability in Microfocus Application Automation Tools
Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin.
network
low complexity
microfocus CWE-862
6.5
2021-04-08 CVE-2021-22512 Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Application Automation Tools
Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin.
network
low complexity
microfocus CWE-352
6.5
2021-04-08 CVE-2021-22511 Improper Certificate Validation vulnerability in Microfocus Application Automation Tools
Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin.
network
low complexity
microfocus CWE-295
6.5
2021-04-08 CVE-2021-22510 Cross-site Scripting vulnerability in Microfocus Application Automation Tools
Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin.
network
low complexity
microfocus CWE-79
6.1
2021-04-08 CVE-2021-22507 Improper Authentication vulnerability in Microfocus Operations Bridge Manager
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10.
network
low complexity
microfocus CWE-287
critical
9.8
2021-03-26 CVE-2021-22506 Unspecified vulnerability in Microfocus Access Manager
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0.
network
low complexity
microfocus
7.5
2021-03-26 CVE-2020-25840 Cross-site Scripting vulnerability in Microfocus Access Manager
Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0.
network
low complexity
microfocus CWE-79
6.1
2021-03-25 CVE-2021-22496 Improper Authentication vulnerability in Microfocus Access Manager
Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3.
network
low complexity
microfocus CWE-287
7.5
2021-02-26 CVE-2019-18947 Information Exposure Through an Error Message vulnerability in Microfocus Solutions Business Manager
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.
low complexity
microfocus CWE-209
3.5