Vendor CVEs
Microfocus
All CVEs
2,790 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38753 | Med | 0.41 | 6.3 | 0.00 | Nov 28, 2022 | This update resolves a multi-factor authentication bypass attack | ||
| CVE-2019-18567 | Med | 0.41 | 6.3 | 0.00 | Feb 3, 2020 | Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service. | ||
| CVE-2019-5407 | Med | 0.41 | 6.3 | 0.01 | Aug 9, 2019 | A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | ||
| CVE-2019-5400 | Med | 0.41 | 6.3 | 0.01 | Aug 9, 2019 | A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | ||
| CVE-2018-7125 | Med | 0.41 | 6.3 | 0.02 | Jun 5, 2019 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | ||
| CVE-2019-2684 | Med | 0.41 | 5.9 | 0.38 | Apr 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network… | ||
| CVE-2018-18589 | Med | 0.41 | 6.3 | 0.01 | Oct 23, 2018 | A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code. | ||
| CVE-2017-5813 | Med | 0.41 | 6.3 | 0.02 | Feb 15, 2018 | A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. | ||
| CVE-2016-2107 | Med | 0.41 | 5.9 | 0.89 | May 5, 2016 | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE:… | ||
| CVE-2015-6864 | Med | 0.41 | 6.3 | 0.01 | Jan 16, 2016 | HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. | ||
| CVE-2026-11878 | Med | 0.40 | 6.1 | 0.00 | Jun 24, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2. | ||
| CVE-2025-43484 | Med | 0.40 | 6.1 | 0.00 | Jul 23, 2025 | A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issue in the latest software… | ||
| CVE-2021-38134 | Med | 0.40 | 6.1 | 0.00 | Nov 22, 2024 | Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000. | ||
| CVE-2021-38119 | Med | 0.40 | 6.1 | 0.00 | Nov 22, 2024 | Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. | ||
| CVE-2024-9841 | Med | 0.40 | 6.1 | 0.00 | Nov 8, 2024 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited. | ||
| CVE-2021-38122 | Med | 0.40 | 6.2 | 0.00 | Aug 28, 2024 | A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1 | ||
| CVE-2024-41910 | Med | 0.40 | 6.1 | 0.00 | Aug 6, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used. | ||
| CVE-2024-2300 | Med | 0.40 | 6.2 | 0.00 | Jun 12, 2024 | HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. | ||
| CVE-2023-5113 | Med | 0.40 | 6.1 | 0.00 | Oct 4, 2023 | Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to WS-Print request and potential injections of Cross Site Scripting via jQuery-UI. | ||
| CVE-2015-1390 | Med | 0.40 | 6.1 | 0.00 | Sep 5, 2023 | Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator. | ||
| CVE-2023-24469 | Med | 0.40 | 6.1 | 0.00 | Jun 13, 2023 | Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0 | ||
| CVE-2023-28092 | Med | 0.40 | 6.1 | 0.00 | May 1, 2023 | A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could result in the system being vulnerable to exploits by attackers with physical access inside the server chassis. | ||
| CVE-2022-26331 | Med | 0.40 | 6.1 | 0.00 | Aug 31, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2… | ||
| CVE-2022-23706 | Med | 0.40 | 6.1 | 0.01 | May 17, 2022 | A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2021-22531 | Med | 0.40 | 6.1 | 0.01 | May 12, 2022 | A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0 | ||
| CVE-2022-23697 | Med | 0.40 | 6.1 | 0.01 | Apr 4, 2022 | A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2021-38127 | Med | 0.40 | 6.1 | 0.01 | Jan 14, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS). | ||
| CVE-2021-38126 | Med | 0.40 | 6.1 | 0.01 | Jan 14, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS). | ||
| CVE-2019-18914 | Med | 0.40 | 6.1 | 0.01 | Nov 9, 2021 | A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link. | ||
| CVE-2021-38123 | Med | 0.40 | 6.1 | 0.01 | Sep 7, 2021 | Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication. | ||
| CVE-2021-26584 | Med | 0.40 | 6.1 | 0.01 | Jun 3, 2021 | A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC). | ||
| CVE-2021-26582 | Med | 0.40 | 6.1 | 0.01 | Apr 15, 2021 | A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS). | ||
| CVE-2020-25840 | Med | 0.40 | 6.1 | 0.01 | Mar 26, 2021 | Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction. | ||
| CVE-2019-18943 | Med | 0.40 | 6.1 | 0.01 | Feb 26, 2021 | Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations. | ||
| CVE-2020-11860 | Med | 0.40 | 6.1 | 0.01 | Nov 17, 2020 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS) | ||
| CVE-2020-7140 | Med | 0.40 | 6.1 | 0.01 | Jul 8, 2020 | A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw:… | ||
| CVE-2020-9522 | Med | 0.40 | 6.1 | 0.01 | Jun 16, 2020 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure. | ||
| CVE-2020-11839 | Med | 0.40 | 6.1 | 0.01 | Jun 12, 2020 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure. | ||
| CVE-2020-11845 | Med | 0.40 | 6.1 | 0.01 | May 19, 2020 | Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers to inject arbitrary web script or HTML. | ||
| CVE-2020-7208 | Med | 0.40 | 6.1 | 0.01 | Feb 13, 2020 | LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2. | ||
| CVE-2012-6344 | Med | 0.40 | 6.1 | 0.01 | Jan 25, 2020 | Novell ZENworks Configuration Management before 11.2.4 allows XSS. | ||
| CVE-2019-11997 | Med | 0.40 | 6.1 | 0.01 | Jan 16, 2020 | A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0. The vulnerability could be used for unauthorized access to information via cross site scripting. HPE has made the following software updates to resolve the… | ||
| CVE-2019-11992 | Med | 0.40 | 6.1 | 0.01 | Dec 18, 2019 | A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting. | ||
| CVE-2019-11651 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. The vulnerability could be exploited to redirect a user to a malicious page or forge certain… | ||
| CVE-2019-11647 | Med | 0.40 | 6.1 | 0.01 | Jun 24, 2019 | A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack. | ||
| CVE-2019-6323 | Med | 0.40 | 6.1 | 0.02 | Jun 17, 2019 | HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to reflected XSS in wireless configuration page. | ||
| CVE-2019-3477 | Med | 0.40 | 6.1 | 0.01 | Jun 7, 2019 | Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect. | ||
| CVE-2019-3490 | Med | 0.40 | 6.1 | 0.01 | May 2, 2019 | A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions… | ||
| CVE-2018-7117 | Med | 0.40 | 6.1 | 0.02 | Apr 9, 2019 | A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40. | ||
| CVE-2018-19641 | Med | 0.40 | 6.1 | 0.01 | Mar 27, 2019 | Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. |
- risk 0.41cvss 6.3epss 0.00
This update resolves a multi-factor authentication bypass attack
- risk 0.41cvss 6.3epss 0.00
Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service.
- risk 0.41cvss 6.3epss 0.01
A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
- risk 0.41cvss 6.3epss 0.01
A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
- risk 0.41cvss 6.3epss 0.02
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
- risk 0.41cvss 5.9epss 0.38
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network…
- risk 0.41cvss 6.3epss 0.01
A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.
- risk 0.41cvss 6.3epss 0.02
A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
- risk 0.41cvss 5.9epss 0.89
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE:…
- risk 0.41cvss 6.3epss 0.01
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
- risk 0.40cvss 6.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.
- risk 0.40cvss 6.1epss 0.00
A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issue in the latest software…
- risk 0.40cvss 6.1epss 0.00
Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.
- risk 0.40cvss 6.1epss 0.00
Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
- risk 0.40cvss 6.1epss 0.00
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.
- risk 0.40cvss 6.2epss 0.00
A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1
- risk 0.40cvss 6.1epss 0.00
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used.
- risk 0.40cvss 6.2epss 0.00
HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.
- risk 0.40cvss 6.1epss 0.00
Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to WS-Print request and potential injections of Cross Site Scripting via jQuery-UI.
- risk 0.40cvss 6.1epss 0.00
Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.
- risk 0.40cvss 6.1epss 0.00
Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0
- risk 0.40cvss 6.1epss 0.00
A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could result in the system being vulnerable to exploits by attackers with physical access inside the server chassis.
- risk 0.40cvss 6.1epss 0.00
Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2…
- risk 0.40cvss 6.1epss 0.01
A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.40cvss 6.1epss 0.01
A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0
- risk 0.40cvss 6.1epss 0.01
A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.40cvss 6.1epss 0.01
Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.
- risk 0.40cvss 6.1epss 0.01
Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.
- risk 0.40cvss 6.1epss 0.01
A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).
- risk 0.40cvss 6.1epss 0.01
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction.
- risk 0.40cvss 6.1epss 0.01
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.
- risk 0.40cvss 6.1epss 0.01
Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS)
- risk 0.40cvss 6.1epss 0.01
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw:…
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers to inject arbitrary web script or HTML.
- risk 0.40cvss 6.1epss 0.01
LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.
- risk 0.40cvss 6.1epss 0.01
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
- risk 0.40cvss 6.1epss 0.01
A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0. The vulnerability could be used for unauthorized access to information via cross site scripting. HPE has made the following software updates to resolve the…
- risk 0.40cvss 6.1epss 0.01
A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting.
- risk 0.40cvss 6.1epss 0.01
Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. The vulnerability could be exploited to redirect a user to a malicious page or forge certain…
- risk 0.40cvss 6.1epss 0.01
A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.
- risk 0.40cvss 6.1epss 0.02
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to reflected XSS in wireless configuration page.
- risk 0.40cvss 6.1epss 0.01
Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.
- risk 0.40cvss 6.1epss 0.01
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions…
- risk 0.40cvss 6.1epss 0.02
A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.
- risk 0.40cvss 6.1epss 0.01
Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
Page 22 of 56