VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2023-4694HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when sending a SOAP message to the service on TCP port 3911 that contains a body but no header.

  • CVE-2023-45624HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-45623HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-45622HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-45621HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-45620HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-4499HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.

  • CVE-2023-1707HigJun 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6.

  • CVE-2023-22787HigMay 8, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected…

  • CVE-2022-43780HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.

  • CVE-2022-2794HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.

  • CVE-2022-23704HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.02

    A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow remote Denial of Service. The vulnerability is resolved in Integrated Lights-Out 4 (iLO 4) 2.80 and later.

  • CVE-2022-23698HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2022-24291HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.05

    Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

  • CVE-2021-3965HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.05

    Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.

  • CVE-2021-3704HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.01

    Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow a Denial of Service on the device.

  • CVE-2021-26586HigAug 5, 2021
    risk 0.49cvss 7.5epss 0.02

    A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates…

  • CVE-2021-22523HigJul 22, 2021
    risk 0.49cvss 7.6epss 0.01

    XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.

  • CVE-2021-22516HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file.

  • CVE-2021-22496HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.

  • CVE-2020-25837HigNov 5, 2020
    risk 0.49cvss 7.5epss 0.01

    Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.

  • CVE-2020-11158HigSep 8, 2020
    risk 0.49cvss 7.5epss 0.01

    u'Null pointer dereference in HP OfficeJet Pro 8210 jbig2 filter due to lack of check of PDF font array leads to denial of service' in IPS PDF releases prior to IPS System 2020.2

  • CVE-2020-11848HigAug 19, 2020
    risk 0.49cvss 7.5epss 0.01

    Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions prior to version 2.9.5. The vulnerability could cause the server to become unavailable, causing a denial of service.

  • CVE-2020-11842HigMay 4, 2020
    risk 0.49cvss 7.5epss 0.01

    Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier than 7.8 Update 1 (7.8.49 or 7.8.0.49). The vulnerability allows an unauthenticated attackers to view information they may not have been authorized to view.

  • CVE-2020-7130HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.02

    HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is resolved in OVGD 1.91 or later.

  • CVE-2015-2802HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.06

    An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive…

  • CVE-2012-6345HigJan 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.

  • CVE-2019-11993HigJan 3, 2020
    risk 0.49cvss 7.5epss 0.02

    A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell…

  • CVE-2019-11995HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release…

  • CVE-2019-17087HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and download files from the filesystem of the system running AcuToWeb, with the privileges of the account AcuToWeb is running under.

  • CVE-2019-6335HigOct 11, 2019
    risk 0.49cvss 7.5epss 0.02

    A potential security vulnerability has been identified with Samsung Laser Printers. This vulnerability could potentially be exploited to create a denial of service.

  • CVE-2019-11665HigSep 17, 2019
    risk 0.49cvss 7.5epss 0.01

    Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

  • CVE-2019-11667HigSep 17, 2019
    risk 0.49cvss 7.5epss 0.01

    Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to private data.

  • CVE-2019-11669HigSep 10, 2019
    risk 0.49cvss 7.5epss 0.01

    Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62. This vulnerability could be exploited to allow unauthorized modification of data.

  • CVE-2019-11668HigSep 10, 2019
    risk 0.49cvss 7.5epss 0.01

    HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Server, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Service…

  • CVE-2019-11654HigAug 23, 2019
    risk 0.49cvss 7.5epss 0.03

    Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files.

  • CVE-2019-11648HigJun 24, 2019
    risk 0.49cvss 7.5epss 0.01

    An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information.

  • CVE-2016-1600HigMay 9, 2019
    risk 0.49cvss 7.5epss 0.01

    The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.

  • CVE-2019-2602HigApr 23, 2019
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2019-3489HigApr 1, 2019
    risk 0.49cvss 7.5epss 0.02

    An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to…

  • CVE-2017-2748HigMar 27, 2019
    risk 0.49cvss 7.5epss 0.02

    A potential security vulnerability caused by the use of insecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app. HP has no access to customer data as a result of this issue.

  • CVE-2016-9166HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.01

    NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.

  • CVE-2018-17950HigDec 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2

  • CVE-2018-12469HigOct 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2…

  • CVE-2018-7102HigSep 27, 2018
    risk 0.49cvss 7.5epss 0.04

    A security vulnerability in HPE Intelligent Management Center (iMC) PLAT E0506P09, createFabricAutoCfgFile could be remotely exploited via directory traversal to allow remote arbitrary file modification.

  • CVE-2018-7101HigSep 27, 2018
    risk 0.49cvss 7.5epss 0.04

    A potential remote denial of service security vulnerability has been identified in HPE Integrated Lights Out 4 prior to v2.60 and iLO 5 for Gen 10 servers prior to v1.30.

  • CVE-2018-6505HigSep 20, 2018
    risk 0.49cvss 7.5epss 0.03

    A potential Unauthenticated File Download vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Unauthenticated File Downloads.

  • CVE-2018-6500HigSep 20, 2018
    risk 0.49cvss 7.5epss 0.04

    A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be remotely exploited to allow Directory Traversal.

  • CVE-2018-7077HigAug 14, 2018
    risk 0.49cvss 7.5epss 0.03

    A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior to 8.6.0-00), Configuration Manager (CM 8.5.0-00 and prior to 8.6.0-00) could be exploited to allow local and remote unauthorized access to sensitive…

  • CVE-2018-7686HigAug 9, 2018
    risk 0.49cvss 7.5epss 0.01

    Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.

Page 17 of 56