Vulnerability index

Browse CVEs

245 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Identity Manager CRITICAL 9.8
CVE-2020-11849

Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix …

Fix: 4.7.3+
Fix from $2,300 2020-07-08
Arcsight Enterprise Security Manager Express MEDIUM 6.1
CVE-2020-9522

Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 .…

Fix: after 7.2.1
Fix from $1,600 2020-06-16
Arcsight Management Center MEDIUM 5.4
CVE-2020-11838

Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.…

Fix: 2.9.4+
Fix from $1,600 2020-06-16
Arcsight Logger MEDIUM 6.1
CVE-2020-11839

Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabil…

Fix: after 7.0.1
Fix from $1,600 2020-06-12
Service Management Automation CRITICAL 9.8
CVE-2020-11844

Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions …

Mitigation only
Fix from $2,300 2020-05-29
Service Manager MEDIUM 6.1
CVE-2020-11845

Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerabi…

Fix: after 9.63
Fix from $1,600 2020-05-19
Enterprise Developer MEDIUM 5.4
CVE-2020-9524

Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Updat…

Mitigation only
Fix from $1,600 2020-05-18
Verastream Host Integrator HIGH 7.5
CVE-2020-11842

Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier than 7.8 Update 1 (7.8.49 or…

Fix: after 7.7
Fix from $1,950 2020-05-04
Enterprise Developer HIGH 8.8
CVE-2020-9523

Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patc…

Fix: after 3.0
Fix from $1,950 2020-04-17
Service Manager Automation HIGH 8.8
CVE-2020-9521

An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08,…

Mitigation only
Fix from $1,950 2020-03-26
Vibe MEDIUM 5.4
CVE-2020-9520

A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote att…

Fix: 4.0.7+
Fix from $1,600 2020-03-25
Service Manager MEDIUM 5.3
CVE-2020-9518

Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61,…

Fix: after 9.62
Fix from $1,600 2020-03-16
Service Manager MEDIUM 5.3
CVE-2020-9519

HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.…

Fix: after 9.63
Fix from $1,600 2020-03-16
Service Manager MEDIUM 5.4
CVE-2020-9517

There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60.…

Mitigation only
Fix from $1,600 2020-03-09
Arcsight Logger HIGH 8.8
CVE-2019-11657

Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could…

Fix: 7.0+
Fix from $1,950 2019-12-17
Acutoweb HIGH 7.5
CVE-2019-17087

Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and dow…

Fix: 10.3+
Fix from $1,950 2019-12-11
Operations Agent MEDIUM 6.5
CVE-2019-17085

XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerab…

Mitigation only
Fix from $1,600 2019-11-18
Netiq Self Service Password Reset MEDIUM 5.9
CVE-2019-11674

Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit …

Fix: after 4.3
Fix from $1,600 2019-10-22
Enterprise Developer MEDIUM 6.1
CVE-2019-11651

Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update …

Mitigation only
Fix from $1,600 2019-10-02
Service Manager MEDIUM 6.5
CVE-2019-11663

Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, …

Fix: after 9.62
Fix from $1,600 2019-09-18
Service Manager MEDIUM 6.5
CVE-2019-11664

Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60…

Fix: after 9.62
Fix from $1,600 2019-09-18
Service Manager HIGH 8.3
CVE-2019-11661

Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.5…

Fix: after 9.62
Fix from $1,950 2019-09-18
Service Manager HIGH 7.5
CVE-2019-11665

Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The…

Fix: after 9.62
Fix from $1,950 2019-09-17
Service Manager HIGH 8.8
CVE-2019-11666

Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51…

Fix: after 9.62
Fix from $1,950 2019-09-17
Service Manager HIGH 7.5
CVE-2019-11667

Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could…

Fix: after 9.62
Fix from $1,950 2019-09-17
Data Protector HIGH 7.8
CVE-2019-11660EPSS 8%

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability cou…

Fix: after 10.40
Fix from $1,950 2019-09-13
Service Manager HIGH 7.5
CVE-2019-11668

HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Fo…

No fix yet
Fix from $1,950 2019-09-10
Service Manager HIGH 7.5
CVE-2019-11669

Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62. This vulnerability could be exploited to allow unauthoriz…

Mitigation only
Fix from $1,950 2019-09-10
Verastream Host Integrator HIGH 7.5
CVE-2019-11654

Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthent…

Mitigation only
Fix from $1,950 2019-08-23
Netiq Self Service Password Reset CRITICAL 9.8
CVE-2019-11652

A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. …

Fix: 4.2.0.6 / 4.3.0.6+
Fix from $2,300 2019-08-14