VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2022-38753MedNov 28, 2022
    risk 0.41cvss 6.3epss 0.00

    This update resolves a multi-factor authentication bypass attack

  • CVE-2019-18567MedFeb 3, 2020
    risk 0.41cvss 6.3epss 0.00

    Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service.

  • CVE-2019-5407MedAug 9, 2019
    risk 0.41cvss 6.3epss 0.01

    A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

  • CVE-2019-5400MedAug 9, 2019
    risk 0.41cvss 6.3epss 0.01

    A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2018-7125MedJun 5, 2019
    risk 0.41cvss 6.3epss 0.02

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-2684MedApr 23, 2019
    risk 0.41cvss 5.9epss 0.38

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network…

  • CVE-2018-18589MedOct 23, 2018
    risk 0.41cvss 6.3epss 0.01

    A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.

  • CVE-2017-5813MedFeb 15, 2018
    risk 0.41cvss 6.3epss 0.02

    A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

  • CVE-2016-2107MedMay 5, 2016
    risk 0.41cvss 5.9epss 0.89

    The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE:…

  • CVE-2015-6864MedJan 16, 2016
    risk 0.41cvss 6.3epss 0.01

    HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.

  • CVE-2026-11878MedJun 24, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.

  • CVE-2025-43484MedJul 23, 2025
    risk 0.40cvss 6.1epss 0.00

    A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issue in the latest software…

  • CVE-2021-38134MedNov 22, 2024
    risk 0.40cvss 6.1epss 0.00

    Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.

  • CVE-2021-38119MedNov 22, 2024
    risk 0.40cvss 6.1epss 0.00

    Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

  • CVE-2024-9841MedNov 8, 2024
    risk 0.40cvss 6.1epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

  • CVE-2021-38122MedAug 28, 2024
    risk 0.40cvss 6.2epss 0.00

    A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1

  • CVE-2024-41910MedAug 6, 2024
    risk 0.40cvss 6.1epss 0.00

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used.

  • CVE-2024-2300MedJun 12, 2024
    risk 0.40cvss 6.2epss 0.00

    HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.

  • CVE-2023-5113MedOct 4, 2023
    risk 0.40cvss 6.1epss 0.00

    Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to WS-Print request and potential injections of Cross Site Scripting via jQuery-UI.

  • CVE-2015-1390MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.

  • CVE-2023-24469MedJun 13, 2023
    risk 0.40cvss 6.1epss 0.00

    Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0

  • CVE-2023-28092MedMay 1, 2023
    risk 0.40cvss 6.1epss 0.00

    A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could result in the system being vulnerable to exploits by attackers with physical access inside the server chassis.

  • CVE-2022-26331MedAug 31, 2022
    risk 0.40cvss 6.1epss 0.00

    Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2…

  • CVE-2022-23706MedMay 17, 2022
    risk 0.40cvss 6.1epss 0.01

    A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2021-22531MedMay 12, 2022
    risk 0.40cvss 6.1epss 0.01

    A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0

  • CVE-2022-23697MedApr 4, 2022
    risk 0.40cvss 6.1epss 0.01

    A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2021-38127MedJan 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).

  • CVE-2021-38126MedJan 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).

  • CVE-2019-18914MedNov 9, 2021
    risk 0.40cvss 6.1epss 0.01

    A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.

  • CVE-2021-38123MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.

  • CVE-2021-26584MedJun 3, 2021
    risk 0.40cvss 6.1epss 0.01

    A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).

  • CVE-2021-26582MedApr 15, 2021
    risk 0.40cvss 6.1epss 0.01

    A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).

  • CVE-2020-25840MedMar 26, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction.

  • CVE-2019-18943MedFeb 26, 2021
    risk 0.40cvss 6.1epss 0.01

    Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.

  • CVE-2020-11860MedNov 17, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS)

  • CVE-2020-7140MedJul 8, 2020
    risk 0.40cvss 6.1epss 0.01

    A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw:…

  • CVE-2020-9522MedJun 16, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.

  • CVE-2020-11839MedJun 12, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.

  • CVE-2020-11845MedMay 19, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers to inject arbitrary web script or HTML.

  • CVE-2020-7208MedFeb 13, 2020
    risk 0.40cvss 6.1epss 0.01

    LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.

  • CVE-2012-6344MedJan 25, 2020
    risk 0.40cvss 6.1epss 0.01

    Novell ZENworks Configuration Management before 11.2.4 allows XSS.

  • CVE-2019-11997MedJan 16, 2020
    risk 0.40cvss 6.1epss 0.01

    A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0. The vulnerability could be used for unauthorized access to information via cross site scripting. HPE has made the following software updates to resolve the…

  • CVE-2019-11992MedDec 18, 2019
    risk 0.40cvss 6.1epss 0.01

    A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting.

  • CVE-2019-11651MedOct 2, 2019
    risk 0.40cvss 6.1epss 0.01

    Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. The vulnerability could be exploited to redirect a user to a malicious page or forge certain…

  • CVE-2019-11647MedJun 24, 2019
    risk 0.40cvss 6.1epss 0.01

    A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.

  • CVE-2019-6323MedJun 17, 2019
    risk 0.40cvss 6.1epss 0.02

    HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to reflected XSS in wireless configuration page.

  • CVE-2019-3477MedJun 7, 2019
    risk 0.40cvss 6.1epss 0.01

    Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.

  • CVE-2019-3490MedMay 2, 2019
    risk 0.40cvss 6.1epss 0.01

    A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions…

  • CVE-2018-7117MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.02

    A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out 5 (iLO 5) for Gen10 ProLiant Servers earlier than version v1.40.

  • CVE-2018-19641MedMar 27, 2019
    risk 0.40cvss 6.1epss 0.01

    Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

Page 22 of 56