VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2019-3480MedMar 25, 2019
    risk 0.40cvss 6.1epss 0.02

    Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.

  • CVE-2018-17952MedDec 12, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross site scripting vulnerability in eDirectory prior to 9.1 SP2

  • CVE-2018-17949MedDec 12, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross site scripting vulnerability in iManager prior to 3.1 SP2.

  • CVE-2018-17948MedNov 20, 2018
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.

  • CVE-2018-12480MedNov 15, 2018
    risk 0.40cvss 6.1epss 0.01

    Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.

  • CVE-2018-7692MedAug 9, 2018
    risk 0.40cvss 6.1epss 0.01

    Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.

  • CVE-2018-7091MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.01

    HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.

  • CVE-2018-7090MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.01

    HPE XP P9000 Command View Advanced Edition Software (CVAE) has local and remote cross site scripting vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.

  • CVE-2018-7075MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.01

    A remote cross-site scripting (XSS) vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT version v7.3 (E0506). The vulnerability is fixed in Intelligent Management Center PLAT 7.3 E0605P04 or subsequent version.

  • CVE-2018-7068MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.01

    HPE has identified a remote HOST header attack vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

  • CVE-2017-9002MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.01

    All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session…

  • CVE-2016-4406MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.03

    A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.

  • CVE-2018-7680MedJun 21, 2018
    risk 0.40cvss 6.1epss 0.01

    Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.

  • CVE-2018-9027MedJun 18, 2018
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.

  • CVE-2017-8945MedFeb 15, 2018
    risk 0.40cvss 6.1epss 0.02

    A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.

  • CVE-2016-8517MedFeb 15, 2018
    risk 0.40cvss 6.1epss 0.02

    A cross site scripting vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.

  • CVE-2017-2746MedJan 23, 2018
    risk 0.40cvss 6.1epss 0.01

    Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to create a denial of service.

  • CVE-2017-2745MedJan 23, 2018
    risk 0.40cvss 6.1epss 0.01

    Potential security vulnerabilities have been identified with HP JetAdvantage Security Manager before 3.0.1. The vulnerabilities could potentially be exploited to allow stored cross-site scripting which could allow a hacker to execute scripts in a user's browser.

  • CVE-2017-2743MedJan 23, 2018
    risk 0.40cvss 6.1epss 0.02

    HP has identified a potential security vulnerability with HP Enterprise LaserJet Printers and MFPs, HP OfficeJet Enterprise Color Printers and MFP, HP PageWide Color Printers and MPS before 2308214_000901, 2308214_000900, and other firmware versions. The vulnerability could be…

  • CVE-2018-2641MedJan 18, 2018
    risk 0.40cvss 6.1epss 0.05

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with…

  • CVE-2017-14358MedOct 31, 2017
    risk 0.40cvss 6.1epss 0.02

    A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.

  • CVE-2017-14357MedOct 31, 2017
    risk 0.40cvss 6.1epss 0.02

    A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS)

  • CVE-2017-14354MedOct 5, 2017
    risk 0.40cvss 6.1epss 0.02

    A remote cross-site scripting vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33 could be remotely exploited to allow cross-site scripting.

  • CVE-2017-14352MedSep 30, 2017
    risk 0.40cvss 6.1epss 0.01

    A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow cross-site scripting.

  • CVE-2017-13986MedSep 30, 2017
    risk 0.40cvss 6.1epss 0.01

    A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system.

  • CVE-2017-7421MedAug 21, 2017
    risk 0.40cvss 6.1epss 0.02

    Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1…

  • CVE-2017-7430MedMay 3, 2017
    risk 0.40cvss 6.1epss 0.01

    Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.

  • CVE-2017-5191MedApr 24, 2017
    risk 0.40cvss 6.1epss 0.01

    An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.

  • CVE-2017-5183MedApr 20, 2017
    risk 0.40cvss 6.1epss 0.01

    NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.

  • CVE-2016-5761MedApr 20, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.

  • CVE-2016-5760MedApr 20, 2017
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2)…

  • CVE-2016-5756MedMar 23, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple components of the web tools in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 were vulnerable to Reflected Cross Site Scripting attacks which could be used to hijack user sessions: nps/servlet/frameservice, nps/servlet/webacc, roma/admin/cntl,…

  • CVE-2016-5751MedMar 23, 2017
    risk 0.40cvss 6.1epss 0.01

    An unfiltered finalizer target URL in the SAML processing feature in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 could be used to trigger XSS and leak authentication credentials.

  • CVE-2016-1592MedOct 27, 2016
    risk 0.40cvss 6.1epss 0.01

    XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.

  • CVE-2015-0787MedOct 27, 2016
    risk 0.40cvss 6.1epss 0.01

    XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.

  • CVE-2016-4363MedJun 8, 2016
    risk 0.40cvss 6.1epss 0.03

    HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors.

  • CVE-2016-1599MedMar 24, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

  • CVE-2024-2207MedNov 12, 2024
    risk 0.39cvss 6.0epss 0.00

    Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.

  • CVE-2021-22527MedSep 13, 2021
    risk 0.39cvss 6.0epss 0.01

    Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

  • CVE-2019-18618MedJul 22, 2020
    risk 0.39cvss 6.0epss 0.01

    Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an…

  • CVE-2018-2973MedJul 18, 2018
    risk 0.39cvss 5.9epss 0.05

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with…

  • CVE-2018-6490MedMar 2, 2018
    risk 0.39cvss 5.9epss 0.03

    Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service.

  • CVE-2018-2618MedJan 18, 2018
    risk 0.39cvss 5.9epss 0.05

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows…

  • CVE-2017-14360MedNov 8, 2017
    risk 0.39cvss 5.9epss 0.02

    A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited to allow Denial of Service (DoS).

  • CVE-2016-8106MedJan 9, 2017
    risk 0.39cvss 5.9epss 0.04

    A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.

  • CVE-2016-2244MedMar 4, 2016
    risk 0.39cvss 5.9epss 0.03

    HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2000-0972MedDec 19, 2000
    risk 0.39cvss 5.5epss 0.01

    HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.

  • CVE-2026-42626MedMay 22, 2026
    risk 0.38cvss 5.9epss 0.00

    HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can establish a persistent connection to port 9100 and send keep-alive packets,…

  • CVE-2025-0858MedFeb 5, 2025
    risk 0.38cvss —epss 0.00

    A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.

  • CVE-2023-7240MedMay 7, 2024
    risk 0.38cvss 5.8epss 0.00

     An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to…

Page 23 of 56