Vulnerabilities > Microfocus > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-21 CVE-2020-11847 OS Command Injection vulnerability in Microfocus Netiq Privileged Access Manager 3.7
SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash.
local
low complexity
microfocus CWE-78
7.8
2023-12-06 CVE-2023-32268 Insufficiently Protected Credentials vulnerability in Microfocus Filr
Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.
network
low complexity
microfocus CWE-522
7.2
2023-08-11 CVE-2023-32267 Unspecified vulnerability in Microfocus Arcsight Management Center
A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center.
network
low complexity
microfocus
8.8
2022-12-23 CVE-2022-38757 Improper Privilege Management vulnerability in Microfocus Zenworks 2020
A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions.
network
low complexity
microfocus CWE-269
7.2
2022-08-31 CVE-2022-26330 Unspecified vulnerability in Microfocus Arcsight Logger
Potential vulnerabilities have been identified in Micro Focus ArcSight Logger.
network
low complexity
microfocus
7.5
2021-09-13 CVE-2021-22527 Unspecified vulnerability in Microfocus Access Manager 5.0
Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
network
low complexity
microfocus
7.5
2021-08-05 CVE-2021-22517 Unspecified vulnerability in Microfocus Data Protector
A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector.
network
low complexity
microfocus
8.8
2021-07-22 CVE-2021-22522 Cross-site Scripting vulnerability in Microfocus Verastream Host Integrator
Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Update 1 and earlier versions.
network
low complexity
microfocus CWE-79
7.1
2021-07-22 CVE-2021-22523 XXE vulnerability in Microfocus Verastream Host Integrator
XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions.
network
low complexity
microfocus CWE-611
7.6
2021-06-04 CVE-2021-22516 Information Exposure Through Log Files vulnerability in Microfocus Secure API Manager 2.0.0
Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0.
network
low complexity
microfocus CWE-532
7.5