VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2020-11843MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before

  • CVE-2024-0407MedFeb 21, 2024
    risk 0.42cvss 6.5epss 0.00

    Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled by some solutions may have been trusted without the appropriate CA certificate in the device's…

  • CVE-2022-48220MedFeb 14, 2024
    risk 0.42cvss 6.4epss 0.00

    Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.

  • CVE-2022-48219MedFeb 14, 2024
    risk 0.42cvss 6.4epss 0.00

    Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.

  • CVE-2023-32267MedAug 11, 2023
    risk 0.42cvss 6.4epss 0.00

    A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited.

  • CVE-2021-46846MedDec 12, 2022
    risk 0.42cvss 6.4epss 0.01

    Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5.

  • CVE-2022-26330MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.01

    Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2…

  • CVE-2021-38130MedFeb 4, 2022
    risk 0.42cvss 6.5epss 0.01

    A potential Information leakage vulnerability has been identified in versions of Micro Focus Voltage SecureMail Mail Relay prior to 7.3.0.1. The vulnerability could be exploited to create an information leakage attack.

  • CVE-2021-22500MedFeb 6, 2021
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.

  • CVE-2020-25838MedDec 11, 2020
    risk 0.42cvss 6.5epss 0.01

    Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x versions. The vulnerability could be exploited to disclose unauthorized sensitive information.

  • CVE-2020-7196MedOct 26, 2020
    risk 0.42cvss 6.5epss 0.01

    The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the…

  • CVE-2020-7134MedApr 24, 2020
    risk 0.42cvss 6.5epss 0.01

    A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.

  • CVE-2019-18917MedMar 16, 2020
    risk 0.42cvss 6.5epss 0.01

    A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.

  • CVE-2019-17085MedNov 18, 2019
    risk 0.42cvss 6.5epss 0.01

    XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Operations Agent.

  • CVE-2019-11664MedSep 18, 2019
    risk 0.42cvss 6.5epss 0.01

    Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

  • CVE-2019-11663MedSep 18, 2019
    risk 0.42cvss 6.5epss 0.00

    Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

  • CVE-2019-5408MedAug 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are…

  • CVE-2019-11946MedJun 5, 2019
    risk 0.42cvss 6.5epss 0.01

    A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-3483MedMar 25, 2019
    risk 0.42cvss 6.5epss 0.01

    Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.

  • CVE-2018-7109MedSep 27, 2018
    risk 0.42cvss 6.5epss 0.01

    HPE has addressed a remote arbitrary file modification vulnerability in HPE enhanced Internet Usage Manager (eIUM) v9.0FP1 with the cumulative patch for v9.0FP1 - eIUM90FP01XXX.YYYYMMDD-HHMM.

  • CVE-2018-6503MedSep 20, 2018
    risk 0.42cvss 6.5epss 0.01

    A potential Access Control vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for vulnerable Access Controls.

  • CVE-2018-6502MedSep 20, 2018
    risk 0.42cvss 6.5epss 0.01

    A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Reflected Cross-site Scripting (XSS).

  • CVE-2018-6501MedSep 20, 2018
    risk 0.42cvss 6.5epss 0.01

    Potential security vulnerability of Insufficient Access Controls has been identified in ArcSight Management Center (ArcMC) for versions prior to 2.81. This vulnerability could be exploited to allow for insufficient access controls.

  • CVE-2018-7682MedJun 22, 2018
    risk 0.42cvss 6.5epss 0.01

    Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.

  • CVE-2017-5787MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.02

    A remote denial of service vulnerability in HPE Version Control Repository Manager (VCRM) in all versions prior to 7.6 was found.

  • CVE-2017-5785MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.02

    A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-5784MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.01

    A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-5780MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.01

    A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-12560MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.02

    A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.

  • CVE-2017-12559MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.02

    A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.

  • CVE-2017-12543MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.01

    A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.

  • CVE-2016-8514MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.02

    A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

  • CVE-2017-13988MedSep 30, 2017
    risk 0.42cvss 6.5epss 0.01

    An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function.

  • CVE-2017-13987MedSep 30, 2017
    risk 0.42cvss 6.5epss 0.01

    An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.

  • CVE-2017-13985MedSep 30, 2017
    risk 0.42cvss 6.5epss 0.02

    An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclosure of information.

  • CVE-2017-13984MedSep 30, 2017
    risk 0.42cvss 6.5epss 0.03

    An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal.

  • CVE-2017-7424MedAug 21, 2017
    risk 0.42cvss 6.5epss 0.02

    A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to download arbitrary files from a system running the product,…

  • CVE-2017-7433MedMay 18, 2017
    risk 0.42cvss 6.5epss 0.01

    An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed…

  • CVE-2016-5755MedMar 23, 2017
    risk 0.42cvss 6.5epss 0.00

    NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to clickjacking attacks due to a missing SAMEORIGIN filter in the "high encryption" setting.

  • CVE-2016-1603MedMar 23, 2017
    risk 0.42cvss 6.5epss 0.01

    An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users.

  • CVE-2016-5765MedNov 29, 2016
    risk 0.42cvss 6.5epss 0.02

    Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that…

  • CVE-2016-4394MedOct 28, 2016
    risk 0.42cvss 6.5epss 0.03

    HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue.

  • CVE-2016-6306MedSep 26, 2016
    risk 0.42cvss 5.9epss 0.42

    The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

  • CVE-2016-2013MedMay 7, 2016
    risk 0.42cvss 6.5epss 0.02

    HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors.

  • CVE-2016-2012MedMay 7, 2016
    risk 0.42cvss 6.5epss 0.04

    HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors.

  • CVE-2016-1994MedMar 18, 2016
    risk 0.42cvss 6.5epss 0.02

    HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.

  • CVE-2016-1992MedMar 17, 2016
    risk 0.42cvss 6.5epss 0.02

    HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors.

  • CVE-2015-5434MedJan 5, 2016
    risk 0.42cvss 6.5epss 0.03

    HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and forwarding (VRF) hopping."

  • CVE-2021-22529MedAug 28, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1

  • CVE-2024-2209MedMar 27, 2024
    risk 0.41cvss 6.3epss 0.00

    A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary…

Page 21 of 56