VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2017-5825HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A privilege escalation vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

  • CVE-2017-5796HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.

  • CVE-2017-5794HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.03

    A Remote Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.

  • CVE-2017-5781HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2016-8534HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.01

    A remote privilege elevation vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2016-8533HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.01

    A remote priviledge escalation vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2016-8515HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.02

    A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

  • CVE-2017-13982HigSep 30, 2017
    risk 0.57cvss 8.8epss 0.04

    A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files.

  • CVE-2017-7423HigAug 21, 2017
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is…

  • CVE-2017-5187HigAug 21, 2017
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote…

  • CVE-2017-7431HigMay 3, 2017
    risk 0.57cvss 8.8epss 0.01

    Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.

  • CVE-2016-5758HigMar 23, 2017
    risk 0.57cvss 8.8epss 0.01

    A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.

  • CVE-2016-5750HigMar 23, 2017
    risk 0.57cvss 8.8epss 0.01

    The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages that would be executed as the iManager user, allowing code execution by logged-in remote users.

  • CVE-2016-1597HigMar 23, 2017
    risk 0.57cvss 8.8epss 0.01

    A logged-in user in NetIQ Access Governance Suite 6.0 through 6.4 could escalate privileges to administrator.

  • CVE-2016-5387HigJul 19, 2016
    risk 0.57cvss 8.1epss 0.56

    The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP…

  • CVE-2016-5385HigJul 19, 2016
    risk 0.57cvss 8.1epss 0.50

    PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an…

  • CVE-2016-4369HigJun 8, 2016
    risk 0.57cvss 8.8epss 0.02

    HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

  • CVE-2016-3710HigMay 11, 2016
    risk 0.57cvss 8.8epss 0.01

    The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

  • CVE-2016-2009HigMay 7, 2016
    risk 0.57cvss 8.8epss 0.02

    HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

  • CVE-2015-5445HigJan 5, 2016
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2021-38135HigNov 22, 2024
    risk 0.56cvss 8.6epss 0.00

    Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.

  • CVE-2018-7093HigAug 14, 2018
    risk 0.56cvss 8.6epss 0.03

    A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a denial of service.

  • CVE-2017-8987HigAug 6, 2018
    risk 0.56cvss 8.6epss 0.04

    A Unauthenticated Remote Denial of Service vulnerability was identified in HPE Integrated Lights-Out 3 (iLO 3) version v1.88 only. The vulnerability is resolved in iLO3 v1.89 or subsequent versions.

  • CVE-2016-4384HigSep 21, 2016
    risk 0.56cvss 8.6epss 0.05

    HPE Performance Center before 12.50 and LoadRunner before 12.50 allow remote attackers to cause a denial of service via unspecified vectors.

  • CVE-2026-12554HigAug 24, 2026
    risk 0.55cvss —epss 0.00

    Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

  • CVE-2025-10577HigOct 15, 2025
    risk 0.55cvss —epss 0.00

    Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities

  • CVE-2025-10576HigOct 15, 2025
    risk 0.55cvss —epss 0.00

    Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities.

  • CVE-2025-3478HigAug 25, 2025
    risk 0.55cvss —epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.

  • CVE-2025-43490HigAug 15, 2025
    risk 0.55cvss —epss 0.00

    A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support software, which might allow escalation of privilege. HP is releasing software updates to mitigate the potential vulnerability.

  • CVE-2025-1003HigFeb 4, 2025
    risk 0.55cvss —epss 0.00

    A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass which may result in escalation of privilege. HP is releasing a software update to mitigate this potential vulnerability.

  • CVE-2024-1973HigMar 25, 2024
    risk 0.55cvss 8.5epss 0.00

    By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations.

  • CVE-2022-37018HigDec 12, 2022
    risk 0.55cvss 8.4epss 0.00

    A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.

  • CVE-2021-3661HigDec 12, 2022
    risk 0.55cvss 8.4epss 0.00

    A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.

  • CVE-2018-3149HigOct 17, 2018
    risk 0.55cvss 8.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows…

  • CVE-2018-7098HigAug 14, 2018
    risk 0.55cvss 8.4epss 0.01

    A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow directory traversal.

  • CVE-2017-8946HigFeb 15, 2018
    risk 0.55cvss 8.3epss 0.09

    A Remote Code Execution vulnerability in HPE Aruba AirWave Glass version v1.0.0 and 1.0.1 was found.

  • CVE-2016-4383HigJun 27, 2017
    risk 0.55cvss 8.4epss 0.03

    The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.

  • CVE-2016-4364HigJun 8, 2016
    risk 0.55cvss 8.4epss 0.01

    HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors.

  • CVE-2016-1593HigApr 22, 2016
    risk 0.55cvss 7.2epss 0.60

    Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a…

  • CVE-2015-6862HigJan 8, 2016
    risk 0.55cvss 8.4epss 0.02

    HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.

  • CVE-2015-6860HigJan 5, 2016
    risk 0.55cvss 8.4epss 0.01

    HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6859.

  • CVE-2021-38121HigAug 28, 2024
    risk 0.54cvss 8.3epss 0.00

    Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices.  This issue affects NetIQ Advance Authentication versions before 6.3.5.1

  • CVE-2023-28083HigMar 22, 2023
    risk 0.54cvss 8.3epss 0.00

    A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.

  • CVE-2020-11858HigOct 27, 2020
    risk 0.54cvss 7.8epss 0.03

    Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Bridge (containerized). The vulneravility affects: 1.) Operation Bridge Manager versions: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60,…

  • CVE-2020-11855HigSep 22, 2020
    risk 0.54cvss 7.8epss 0.01

    An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with escalated privileges.

  • CVE-2019-18915HigFeb 13, 2020
    risk 0.54cvss 7.8epss 0.01

    A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system service.

  • CVE-2019-11661HigSep 18, 2019
    risk 0.54cvss 8.3epss 0.01

    Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited to allow unauthorized access and modification of data.

  • CVE-2019-11660HigSep 13, 2019
    risk 0.54cvss 7.8epss 0.08

    Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

  • CVE-2019-11982HigJun 5, 2019
    risk 0.54cvss 8.3epss 0.02

    A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

  • CVE-2019-3475HigFeb 20, 2019
    risk 0.54cvss 7.8epss 0.01

    A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

Page 12 of 56