Vulnerabilities > Microfocus

DATE CVE VULNERABILITY TITLE RISK
2020-08-07 CVE-2020-11852 OS Command Injection vulnerability in Microfocus Secure Messaging Gateway 471
DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG).
network
low complexity
microfocus CWE-78
8.8
2020-07-08 CVE-2020-11849 Unspecified vulnerability in Microfocus Identity Manager
Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager.
network
low complexity
microfocus
critical
9.8
2020-06-16 CVE-2020-9522 Cross-site Scripting vulnerability in Microfocus Arcsight Enterprise Security Manager Express 7.0.0/7.2/7.2.1
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 .
network
low complexity
microfocus CWE-79
6.1
2020-06-16 CVE-2020-11841 Unspecified vulnerability in Microfocus Arcsight Management Center
Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4.
network
low complexity
microfocus
4.3
2020-06-16 CVE-2020-11840 Unspecified vulnerability in Microfocus Arcsight Management Center
Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4.
network
low complexity
microfocus
4.3
2020-06-16 CVE-2020-11838 Cross-site Scripting vulnerability in Microfocus Arcsight Management Center
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4.
network
low complexity
microfocus CWE-79
5.4
2020-06-12 CVE-2020-11839 Cross-site Scripting vulnerability in Microfocus Arcsight Logger 6.61/7.0/7.0.1
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1.
network
low complexity
microfocus CWE-79
6.1
2020-05-29 CVE-2020-11844 Incorrect Authorization vulnerability in Microfocus Service Management Automation
Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management.
network
low complexity
microfocus CWE-863
critical
9.8
2020-05-19 CVE-2020-11845 Cross-site Scripting vulnerability in Microfocus Service Manager
Cross Site Scripting vulnerability in Micro Focus Service Manager product.
network
low complexity
microfocus CWE-79
6.1
2020-05-18 CVE-2020-9524 Cross-site Scripting vulnerability in Microfocus Enterprise Developer and Enterprise Server
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8.
network
low complexity
microfocus CWE-79
5.4