VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2018-7115MedDec 3, 2018
    risk 0.36cvss 5.3epss 0.06

    HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001 on Windows. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions.

  • CVE-2018-7112MedDec 3, 2018
    risk 0.36cvss 5.5epss 0.01

    The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system…

  • CVE-2018-7100MedAug 14, 2018
    risk 0.36cvss 5.5epss 0.01

    A potential security vulnerability has been identified in HPE OfficeConnect 1810 Switch Series (HP 1810-24G - P.2.22 and previous versions, HP 1810-48G PK.1.34 and previous versions, HP 1810-8 v2 P.2.22 and previous versions). The vulnerability could allow local disclosure of…

  • CVE-2018-7099MedAug 14, 2018
    risk 0.36cvss 5.5epss 0.01

    A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow disclosure of privileged information.

  • CVE-2018-7073MedAug 6, 2018
    risk 0.36cvss 5.5epss 0.01

    A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

  • CVE-2017-8950MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.01

    A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

  • CVE-2017-8949MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.01

    A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

  • CVE-2017-5809MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.01

    A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

  • CVE-2017-5788MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.01

    A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI was found.

  • CVE-2017-5786MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.01

    A local Unauthorized Data Modification vulnerability in HPE OfficeConnect Network Switches version PT.02.01 including PT.01.03 through PT.01.14

  • CVE-2017-12553MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12552MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12551MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12550MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12549MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12548MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12547MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12546MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-2744MedJan 23, 2018
    risk 0.36cvss 5.5epss 0.01

    The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1.

  • CVE-2016-5749MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.

  • CVE-2016-5748MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to disclose the content of local files to logged-in users.

  • CVE-2016-2023MedMay 30, 2016
    risk 0.36cvss 5.5epss 0.01

    HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.

  • CVE-2016-2016MedMay 14, 2016
    risk 0.36cvss 5.5epss 0.01

    Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and…

  • CVE-2021-38131MedSep 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

  • CVE-2021-22503MedSep 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

  • CVE-2024-41911MedAug 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.

  • CVE-2024-4429MedMay 28, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.

  • CVE-2023-22791MedMay 8, 2023
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the…

  • CVE-2022-38755MedNov 21, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Micro Focus Filr in versions prior to 4.3.1.1. The vulnerability could be exploited to allow a remote unauthenticated attacker to enumerate valid users of the system. Remote unauthenticated user enumeration. This issue affects: Micro Focus…

  • CVE-2021-3662MedOct 29, 2021
    risk 0.35cvss 5.4epss 0.00

    Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS).

  • CVE-2021-22524MedSep 13, 2021
    risk 0.35cvss 5.4epss 0.01

    Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

  • CVE-2021-22513MedApr 8, 2021
    risk 0.35cvss 6.5epss 0.01

    Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow access without permission checks.

  • CVE-2021-22512MedApr 8, 2021
    risk 0.35cvss 6.5epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow form validation without permission checks.

  • CVE-2021-22511MedApr 8, 2021
    risk 0.35cvss 6.5epss 0.00

    Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow unconditionally disabling of SSL/TLS certificates.

  • CVE-2020-7202MedJan 5, 2021
    risk 0.35cvss 5.3epss 0.01

    A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) firmware. The vulnerability could be remotely exploited to disclose the serial number and other information.

  • CVE-2020-25832MedNov 17, 2020
    risk 0.35cvss 5.4epss 0.01

    Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability could be exploited to perform Reflected XSS attack.

  • CVE-2020-25834MedNov 17, 2020
    risk 0.35cvss 5.4epss 0.01

    Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).

  • CVE-2020-11838MedJun 16, 2020
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.

  • CVE-2020-9524MedMay 18, 2020
    risk 0.35cvss 5.4epss 0.01

    Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left…

  • CVE-2020-7132MedApr 23, 2020
    risk 0.35cvss 5.4epss 0.01

    A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and mitigation information to resolve the vulnerability in HPE…

  • CVE-2020-9520MedMar 25, 2020
    risk 0.35cvss 5.4epss 0.01

    A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker…

  • CVE-2020-9518MedMar 16, 2020
    risk 0.35cvss 5.3epss 0.01

    Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to configuration data.

  • CVE-2020-9519MedMar 16, 2020
    risk 0.35cvss 5.3epss 0.01

    HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow exposure of configuration data.

  • CVE-2020-9517MedMar 9, 2020
    risk 0.35cvss 5.4epss 0.00

    There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress attacks.

  • CVE-2019-11656MedOct 4, 2019
    risk 0.35cvss 5.4epss 0.01

    Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').

  • CVE-2019-5398MedAug 9, 2019
    risk 0.35cvss 5.4epss 0.01

    A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2019-11653MedAug 7, 2019
    risk 0.35cvss 5.4epss 0.01

    Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploited to manipulate data stored during another user’s CheckIn request.

  • CVE-2019-2769MedJul 23, 2019
    risk 0.35cvss 5.3epss 0.04

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2019-2762MedJul 23, 2019
    risk 0.35cvss 5.3epss 0.04

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2019-11649MedJun 19, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to execute JavaScript code in user’s browser. The…

Page 25 of 56