Vendor CVEs
Microfocus
All CVEs
2,790 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-25835 | Med | 0.38 | 5.9 | 0.00 | Dec 9, 2023 | A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited resulting in stored Cross-Site Scripting (XSS). | ||
| CVE-2022-23678 | Med | 0.38 | 5.9 | 0.01 | Sep 6, 2022 | A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communications that could allow for an attacker in a privileged network position to intercept sensitive information in Aruba Virtual Intranet Access (VIA) client for… | ||
| CVE-2019-11674 | Med | 0.38 | 5.9 | 0.00 | Oct 22, 2019 | Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack. | ||
| CVE-2019-11989 | Med | 0.38 | 5.9 | 0.02 | Jul 19, 2019 | A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for… | ||
| CVE-2019-11650 | Med | 0.38 | 5.9 | 0.01 | Jul 10, 2019 | A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0. | ||
| CVE-2019-5392 | Med | 0.38 | 5.3 | 0.07 | Jun 5, 2019 | A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | ||
| CVE-2018-9069 | Med | 0.38 | 5.9 | 0.01 | Oct 2, 2018 | In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS. | ||
| CVE-2018-1345 | Med | 0.38 | 5.9 | 0.01 | Mar 21, 2018 | NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack. | ||
| CVE-2017-14363 | Med | 0.38 | 5.9 | 0.01 | Dec 21, 2017 | Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). | ||
| CVE-2016-1596 | Med | 0.38 | 5.4 | 0.03 | Apr 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent,… | ||
| CVE-2016-1987 | Med | 0.38 | 5.9 | 0.02 | Feb 18, 2016 | HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets. | ||
| CVE-2025-8997 | Med | 0.37 | — | 0.00 | Aug 25, 2025 | An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited. | ||
| CVE-2025-43483 | Med | 0.37 | 5.7 | 0.00 | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded cryptographic keys. HP has addressed the issue in the latest software update. | ||
| CVE-2025-43021 | Med | 0.37 | 5.7 | 0.00 | Jul 22, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update. | ||
| CVE-2020-6923 | Med | 0.37 | 5.7 | 0.00 | Dec 19, 2024 | The HP Linux Imaging and Printing (HPLIP) software may potentially be affected by memory buffer overflow. | ||
| CVE-2024-4556 | Med | 0.37 | 5.7 | 0.00 | Aug 28, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects NetIQ Access Manager before 5.0.4 and before 5.1. | ||
| CVE-2024-3484 | Med | 0.37 | 5.7 | 0.01 | May 15, 2024 | Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure. | ||
| CVE-2024-1695 | Med | 0.37 | 5.7 | 0.00 | May 6, 2024 | A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC products, which might allow escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability. | ||
| CVE-2020-10136 | Med | 0.37 | 5.3 | 0.29 | Jun 2, 2020 | IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before… | ||
| CVE-2012-1994 | Med | 0.37 | 5.7 | 0.01 | Feb 10, 2020 | HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information | ||
| CVE-2018-3180 | Med | 0.37 | 5.6 | 0.03 | Oct 17, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows… | ||
| CVE-2017-8969 | Med | 0.37 | 5.7 | 0.01 | Feb 15, 2018 | An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found. | ||
| CVE-2026-3291 | Med | 0.36 | 5.5 | 0.00 | May 6, 2026 | Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities. | ||
| CVE-2025-21992 | Med | 0.36 | 5.5 | 0.00 | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera The HP 5MP Camera (USB ID 0408:5473) reports a HID sensor interface that is not actually implemented. Attempting to access this non-functional sensor via… | ||
| CVE-2021-38118 | Med | 0.36 | 5.5 | 0.00 | Nov 22, 2024 | Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. | ||
| CVE-2024-3488 | Med | 0.36 | 5.6 | 0.00 | May 15, 2024 | File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication. | ||
| CVE-2023-6573 | Med | 0.36 | 5.5 | 0.00 | Jan 23, 2024 | HPE OneView may have a missing passphrase during restore. | ||
| CVE-2023-45626 | Med | 0.36 | 5.5 | 0.01 | Nov 14, 2023 | An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles. | ||
| CVE-2023-30903 | Med | 0.36 | 5.5 | 0.00 | Jun 16, 2023 | HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6. | ||
| CVE-2022-31643 | Med | 0.36 | 5.5 | 0.00 | Apr 28, 2023 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability. | ||
| CVE-2023-28084 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2023 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | ||
| CVE-2023-28090 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2023 | An HPE OneView appliance dump may expose SNMPv3 read credentials | ||
| CVE-2023-28087 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2023 | An HPE OneView appliance dump may expose OneView user accounts | ||
| CVE-2023-28086 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2023 | An HPE OneView appliance dump may expose proxy credential settings | ||
| CVE-2023-28091 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2023 | HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump | ||
| CVE-2022-37935 | Med | 0.36 | 5.5 | 0.00 | Mar 1, 2023 | HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password. | ||
| CVE-2022-1602 | Med | 0.36 | 5.5 | 0.00 | Sep 13, 2022 | A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service Pack 9 (SP9). HP has released Service Pack 10 (SP10) to remediate the potential vulnerability… | ||
| CVE-2022-28625 | Med | 0.36 | 5.5 | 0.00 | Aug 31, 2022 | A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality,… | ||
| CVE-2022-23700 | Med | 0.36 | 5.5 | 0.00 | Apr 4, 2022 | A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2022-23958 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2022 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | ||
| CVE-2022-23957 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2022 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | ||
| CVE-2022-23955 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2022 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | ||
| CVE-2022-23954 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2022 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | ||
| CVE-2022-23956 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2022 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | ||
| CVE-2022-23953 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2022 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | ||
| CVE-2020-6920 | Med | 0.36 | 5.5 | 0.01 | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | ||
| CVE-2022-23456 | Med | 0.36 | 5.5 | 0.00 | Jan 28, 2022 | Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software. | ||
| CVE-2021-22525 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2021 | This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1 | ||
| CVE-2019-18942 | Med | 0.36 | 5.5 | 0.00 | Feb 26, 2021 | Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding. | ||
| CVE-2019-19539 | Med | 0.36 | 5.5 | 0.00 | Jan 27, 2020 | An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can… |
- risk 0.38cvss 5.9epss 0.00
A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited resulting in stored Cross-Site Scripting (XSS).
- risk 0.38cvss 5.9epss 0.01
A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communications that could allow for an attacker in a privileged network position to intercept sensitive information in Aruba Virtual Intranet Access (VIA) client for…
- risk 0.38cvss 5.9epss 0.00
Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.
- risk 0.38cvss 5.9epss 0.02
A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for…
- risk 0.38cvss 5.9epss 0.01
A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0.
- risk 0.38cvss 5.3epss 0.07
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
- risk 0.38cvss 5.9epss 0.01
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
- risk 0.38cvss 5.9epss 0.01
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
- risk 0.38cvss 5.9epss 0.01
Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
- risk 0.38cvss 5.4epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent,…
- risk 0.38cvss 5.9epss 0.02
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.
- risk 0.37cvss —epss 0.00
An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.
- risk 0.37cvss 5.7epss 0.00
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded cryptographic keys. HP has addressed the issue in the latest software update.
- risk 0.37cvss 5.7epss 0.00
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.
- risk 0.37cvss 5.7epss 0.00
The HP Linux Imaging and Printing (HPLIP) software may potentially be affected by memory buffer overflow.
- risk 0.37cvss 5.7epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects NetIQ Access Manager before 5.0.4 and before 5.1.
- risk 0.37cvss 5.7epss 0.01
Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.
- risk 0.37cvss 5.7epss 0.00
A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC products, which might allow escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.
- risk 0.37cvss 5.3epss 0.29
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before…
- risk 0.37cvss 5.7epss 0.01
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
- risk 0.37cvss 5.6epss 0.03
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows…
- risk 0.37cvss 5.7epss 0.01
An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.
- risk 0.36cvss 5.5epss 0.00
Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.
- risk 0.36cvss 5.5epss 0.00
In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera The HP 5MP Camera (USB ID 0408:5473) reports a HID sensor interface that is not actually implemented. Attempting to access this non-functional sensor via…
- risk 0.36cvss 5.5epss 0.00
Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
- risk 0.36cvss 5.6epss 0.00
File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.
- risk 0.36cvss 5.5epss 0.00
HPE OneView may have a missing passphrase during restore.
- risk 0.36cvss 5.5epss 0.01
An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.
- risk 0.36cvss 5.5epss 0.00
HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6.
- risk 0.36cvss 5.5epss 0.00
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability.
- risk 0.36cvss 5.5epss 0.00
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
- risk 0.36cvss 5.5epss 0.00
An HPE OneView appliance dump may expose SNMPv3 read credentials
- risk 0.36cvss 5.5epss 0.00
An HPE OneView appliance dump may expose OneView user accounts
- risk 0.36cvss 5.5epss 0.00
An HPE OneView appliance dump may expose proxy credential settings
- risk 0.36cvss 5.5epss 0.00
HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump
- risk 0.36cvss 5.5epss 0.00
HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.
- risk 0.36cvss 5.5epss 0.00
A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service Pack 9 (SP9). HP has released Service Pack 10 (SP10) to remediate the potential vulnerability…
- risk 0.36cvss 5.5epss 0.00
A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality,…
- risk 0.36cvss 5.5epss 0.00
A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.36cvss 5.5epss 0.00
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
- risk 0.36cvss 5.5epss 0.00
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
- risk 0.36cvss 5.5epss 0.00
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
- risk 0.36cvss 5.5epss 0.00
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
- risk 0.36cvss 5.5epss 0.00
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
- risk 0.36cvss 5.5epss 0.00
Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
- risk 0.36cvss 5.5epss 0.01
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
- risk 0.36cvss 5.5epss 0.00
Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.
- risk 0.36cvss 5.5epss 0.00
This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1
- risk 0.36cvss 5.5epss 0.00
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can…
Page 24 of 56