Vulnerability index

Browse CVEs

245 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Developer HIGH 7.5
CVE-2018-12469

Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus…

Fix: after 2.3
Fix from $1,950 2018-10-12
Arcsight Management Center HIGH 8.8
CVE-2018-6504

A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. …

Fix: 2.81+
Fix from $1,950 2018-09-20
Data Center Automation CRITICAL 9.8
CVE-2018-6498

Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con…

Mitigation only
Fix from $2,300 2018-08-30
Data Center Automation CRITICAL 9.8
CVE-2018-6499

Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con…

Mitigation only
Fix from $2,300 2018-08-30
Edirectory HIGH 7.5
CVE-2018-7686

Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.

Fix: after 9.1.1
Fix from $1,950 2018-08-09
Edirectory MEDIUM 6.1
CVE-2018-7692

Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.

Fix: after 9.1.1
Fix from $1,600 2018-08-09
Groupwise HIGH 7.2
CVE-2018-12468

A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an admini…

Fix: 18.0.2+
Fix from $1,950 2018-08-01
Secure Messaging Gateway CRITICAL 9.8
CVE-2018-12464EPSS 81%

A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated r…

Fix: 471+
Fix from $2,300 2018-06-29
Secure Messaging Gateway HIGH 7.2
CVE-2018-12465EPSS 79%

An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker auth…

Fix: 471+
Fix from $1,950 2018-06-29
Solutions Business Manager MEDIUM 6.5
CVE-2018-7682

Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.

Fix: 11.4+
Fix from $1,600 2018-06-22
Solutions Business Manager CRITICAL 9.8
CVE-2018-7679

Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does …

Fix: 11.4+
Fix from $2,300 2018-06-21
Solutions Business Manager HIGH 7.5
CVE-2018-7683

Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.

Fix: 11.4+
Fix from $1,950 2018-06-21
Solutions Business Manager MEDIUM 6.1
CVE-2018-7680

Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.

Fix: 11.4+
Fix from $1,600 2018-06-21
Universal Cmbd Browser HIGH 8.8
CVE-2018-6496

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which coul…

Fix: after 4.15.1
Fix from $1,950 2018-06-16
Cms Server HIGH 8.8
CVE-2018-6497

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10…

Fix: after 11.0
Fix from $1,950 2018-06-16
Universal Cmdb MEDIUM 5.4
CVE-2018-6495

Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.1…

Mitigation only
Fix from $1,600 2018-05-23
Service Manager MEDIUM 5.4
CVE-2018-6494

Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead t…

Mitigation only
Fix from $1,600 2018-05-22
Client HIGH 7.8
CVE-2018-7687

The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevate privileges via a buffer ove…

Fix: after 2.0
Fix from $1,950 2018-05-21
Ucmdb Configuration Manager CRITICAL 9.8
CVE-2018-6491

Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulne…

Mitigation only
Fix from $2,300 2018-04-24
Sentinel MEDIUM 5.3
CVE-2018-7675

In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does …

Fix: after 8.1
Fix from $1,600 2018-03-07
Edirectory CRITICAL 9.8
CVE-2017-9285

NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.

Fix: after 9.0
Fix from $2,300 2018-03-02
Edirectory HIGH 8.8
CVE-2017-7429

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authen…

Fix: after 8.8.8
Fix from $1,950 2018-03-02
Ucmdb Configuration Manager CRITICAL 9.8
CVE-2018-6488

Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to all…

Mitigation only
Fix from $2,300 2018-02-22
Project And Portfolio Management Center CRITICAL 9.8
CVE-2018-6489

XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to …

Mitigation only
Fix from $2,300 2018-02-22
Universal Cmdb Foundation Software HIGH 7.5
CVE-2018-6487

Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, …

No fix yet
Fix from $1,950 2018-02-20
Project And Portfolio Management MEDIUM 5.4
CVE-2017-8993

A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found.

Mitigation only
Fix from $1,600 2018-02-15
Fortify Audit Workbench CRITICAL 9.8
CVE-2018-6486

XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions…

Mitigation only
Fix from $2,300 2018-02-02
Operations Manager I MEDIUM 5.4
CVE-2017-14363

Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability cou…

No fix yet
Fix from $1,600 2017-12-21
Project And Portfolio Management HIGH 7.4
CVE-2017-14361

Man-In-The-Middle vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow …

No fix yet
Fix from $1,950 2017-12-13
Project And Portfolio Management HIGH 7.3
CVE-2017-14362

Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited …

Mitigation only
Fix from $1,950 2017-12-13