Vulnerability index

Browse CVEs

245 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-11849 Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix … Identity Manager 4.7.3+ Fix from $2,3002020-07-08 MEDIUM 6.1 CVE-2020-9522 Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 .… Arcsight Enterprise Security Manager Express after 7.2.1 Fix from $1,6002020-06-16 MEDIUM 5.4 CVE-2020-11838 Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.… Arcsight Management Center 2.9.4+ Fix from $1,6002020-06-16 MEDIUM 6.1 CVE-2020-11839 Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabil… Arcsight Logger after 7.0.1 Fix from $1,6002020-06-12 CRITICAL 9.8 CVE-2020-11844 Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions … Service Management Automation Mitigation only Fix from $2,3002020-05-29 MEDIUM 6.1 CVE-2020-11845 Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerabi… Service Manager after 9.63 Fix from $1,6002020-05-19 MEDIUM 5.4 CVE-2020-9524 Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Updat… Enterprise Developer Mitigation only Fix from $1,6002020-05-18 HIGH 7.5 CVE-2020-11842 Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier than 7.8 Update 1 (7.8.49 or… Verastream Host Integrator after 7.7 Fix from $1,9502020-05-04 HIGH 8.8 CVE-2020-9523 Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patc… Enterprise Developer after 3.0 Fix from $1,9502020-04-17 HIGH 8.8 CVE-2020-9521 An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08,… Service Manager Automation Mitigation only Fix from $1,9502020-03-26 MEDIUM 5.4 CVE-2020-9520 A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote att… Vibe 4.0.7+ Fix from $1,6002020-03-25 MEDIUM 5.3 CVE-2020-9518 Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61,… Service Manager after 9.62 Fix from $1,6002020-03-16 MEDIUM 5.3 CVE-2020-9519 HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.… Service Manager after 9.63 Fix from $1,6002020-03-16 MEDIUM 5.4 CVE-2020-9517 There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60.… Service Manager Mitigation only Fix from $1,6002020-03-09 HIGH 8.8 CVE-2019-11657 Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could… Arcsight Logger 7.0+ Fix from $1,9502019-12-17 HIGH 7.5 CVE-2019-17087 Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and dow… Acutoweb 10.3+ Fix from $1,9502019-12-11 MEDIUM 6.5 CVE-2019-17085 XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerab… Operations Agent Mitigation only Fix from $1,6002019-11-18 MEDIUM 5.9 CVE-2019-11674 Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit … Netiq Self Service Password Reset after 4.3 Fix from $1,6002019-10-22 MEDIUM 6.1 CVE-2019-11651 Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update … Enterprise Developer Mitigation only Fix from $1,6002019-10-02 MEDIUM 6.5 CVE-2019-11663 Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, … Service Manager after 9.62 Fix from $1,6002019-09-18 MEDIUM 6.5 CVE-2019-11664 Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60… Service Manager after 9.62 Fix from $1,6002019-09-18 HIGH 8.3 CVE-2019-11661 Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.5… Service Manager after 9.62 Fix from $1,9502019-09-18 HIGH 7.5 CVE-2019-11665 Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The… Service Manager after 9.62 Fix from $1,9502019-09-17 HIGH 8.8 CVE-2019-11666 Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51… Service Manager after 9.62 Fix from $1,9502019-09-17 HIGH 7.5 CVE-2019-11667 Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could… Service Manager after 9.62 Fix from $1,9502019-09-17 HIGH 7.8 CVE-2019-11660EPSS 8% Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability cou… Data Protector after 10.40 Fix from $1,9502019-09-13 HIGH 7.5 CVE-2019-11668 HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Fo… Service Manager No fix yet Fix from $1,9502019-09-10 HIGH 7.5 CVE-2019-11669 Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62. This vulnerability could be exploited to allow unauthoriz… Service Manager Mitigation only Fix from $1,9502019-09-10 HIGH 7.5 CVE-2019-11654 Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthent… Verastream Host Integrator Mitigation only Fix from $1,9502019-08-23 CRITICAL 9.8 CVE-2019-11652 A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. … Netiq Self Service Password Reset 4.2.0.6 / 4.3.0.6+ Fix from $2,3002019-08-14