Vulnerabilities > Microfocus > High

DATE CVE VULNERABILITY TITLE RISK
2018-08-09 CVE-2018-7686 Information Exposure vulnerability in Microfocus Edirectory
Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.
network
low complexity
microfocus CWE-200
7.5
2018-08-01 CVE-2018-12468 Unrestricted Upload of File with Dangerous Type vulnerability in Microfocus Groupwise 18/18.0.1
A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server.
network
low complexity
microfocus CWE-434
7.2
2018-06-29 CVE-2018-12465 OS Command Injection vulnerability in Microfocus Secure Messaging Gateway
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server.
network
low complexity
microfocus CWE-78
7.2
2018-06-21 CVE-2018-7683 Information Exposure Through Log Files vulnerability in Microfocus Solutions Business Manager
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.
network
low complexity
microfocus CWE-532
7.5
2018-06-16 CVE-2018-6497 Deserialization of Untrusted Data vulnerability in Microfocus CMS Server and Universal Cmbd Server
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
network
low complexity
microfocus CWE-502
8.8
2018-06-16 CVE-2018-6496 Deserialization of Untrusted Data vulnerability in Microfocus Universal Cmbd Browser
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
network
low complexity
microfocus CWE-502
8.8
2018-05-21 CVE-2018-7687 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microfocus Client 2.0
The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevate privileges via a buffer overflow in ncfsd.sys.
local
low complexity
microfocus CWE-119
7.8
2018-03-02 CVE-2017-7429 Improper Certificate Validation vulnerability in multiple products
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
network
low complexity
netiq microfocus CWE-295
8.8
2018-02-20 CVE-2018-6487 Information Exposure vulnerability in Microfocus Universal Cmdb Foundation Software
Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11.
network
low complexity
microfocus CWE-200
7.5
2017-12-13 CVE-2017-14362 Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Project and Portfolio Management 9.32
Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32.
network
low complexity
microfocus CWE-352
7.3