VYPR

Imanager

by Microfocus

CVEs (35)

  • CVE-2018-17949MedDec 12, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross site scripting vulnerability in iManager prior to 3.1 SP2.

  • CVE-2017-7430MedMay 3, 2017
    risk 0.40cvss 6.1epss 0.01

    Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.

  • CVE-2018-1345MedMar 21, 2018
    risk 0.38cvss 5.9epss 0.01

    NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.

  • CVE-2024-3484MedMay 15, 2024
    risk 0.37cvss 5.7epss 0.01

    Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.

  • CVE-2021-38118MedNov 22, 2024
    risk 0.36cvss 5.5epss 0.00

    Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

  • CVE-2024-3488MedMay 15, 2024
    risk 0.36cvss 5.6epss 0.00

    File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

  • CVE-2024-4429MedMay 28, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.

  • CVE-2018-1347MedMar 21, 2018
    risk 0.35cvss 5.3epss 0.01

    The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.

  • CVE-2017-7428MedMay 3, 2017
    risk 0.35cvss 5.3epss 0.01

    NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.

  • CVE-2024-3970MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.01

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

  • CVE-2024-3485MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.00

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

  • CVE-2018-12462MedJul 10, 2018
    risk 0.31cvss 4.8epss 0.01

    NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.

  • CVE-2017-5189MedMar 2, 2018
    risk 0.28cvss 4.3epss 0.01

    NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.

  • CVE-2024-3487LowMay 15, 2024
    risk 0.23cvss 3.5epss 0.00

    Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.

  • CVE-2018-1344LowMar 21, 2018
    risk 0.20cvss 3.1epss 0.01

    Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1

Page 2 of 2