Vulnerabilities > Microfocus > High

DATE CVE VULNERABILITY TITLE RISK
2019-09-17 CVE-2019-11666 Deserialization of Untrusted Data vulnerability in Microfocus Service Manager
Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62.
network
low complexity
microfocus CWE-502
8.8
2019-09-17 CVE-2019-11667 Unspecified vulnerability in Microfocus Service Manager
Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62.
network
low complexity
microfocus
7.5
2019-09-13 CVE-2019-11660 Untrusted Search Path vulnerability in Microfocus Data Protector
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40.
local
low complexity
microfocus CWE-426
7.8
2019-09-10 CVE-2019-11669 Unspecified vulnerability in Microfocus Service Manager 9.60/9.61/9.62
Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62.
network
low complexity
microfocus
7.5
2019-09-10 CVE-2019-11668 Unspecified vulnerability in Microfocus products
HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62.
network
low complexity
microfocus
7.5
2019-08-23 CVE-2019-11654 Path Traversal vulnerability in Microfocus Verastream Host Integrator 7.5/7.6/7.7
Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files.
network
low complexity
microfocus CWE-22
7.5
2019-06-03 CVE-2019-11646 Unspecified vulnerability in Microfocus Service Manager
Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61.
network
low complexity
microfocus
8.8
2019-05-09 CVE-2016-1600 Information Exposure vulnerability in Microfocus Identity Manager
The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.
network
low complexity
microfocus CWE-200
7.5
2019-04-29 CVE-2019-3493 Unspecified vulnerability in Microfocus Network Automation and Network Operations Management
A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions.
network
low complexity
microfocus
8.8
2019-04-01 CVE-2019-3489 Unrestricted Upload of File with Dangerous Type vulnerability in Microfocus Content Manager
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method.
network
low complexity
microfocus CWE-434
7.5