VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2018-7122MedJun 5, 2019
    risk 0.35cvss 5.3epss 0.02

    A remote disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2018-7111MedOct 17, 2018
    risk 0.35cvss 5.3epss 0.04

    A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by…

  • CVE-2018-3214MedOct 17, 2018
    risk 0.35cvss 5.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulnerability allows…

  • CVE-2018-7070MedAug 6, 2018
    risk 0.35cvss 5.3epss 0.02

    HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

  • CVE-2017-8991MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    HPE has identified a cross site scripting (XSS) vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

  • CVE-2016-4400MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).

  • CVE-2016-4399MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).

  • CVE-2016-4392MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    A remote cross site scripting vulnerability has been identified in HP Business Service Management software v9.1x, v9.20 - v9.25IP1.

  • CVE-2018-9024MedJun 18, 2018
    risk 0.35cvss 5.3epss 0.01

    An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.

  • CVE-2018-6495MedMay 23, 2018
    risk 0.35cvss 5.4epss 0.01

    Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be…

  • CVE-2018-6494MedMay 22, 2018
    risk 0.35cvss 5.4epss 0.01

    Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.

  • CVE-2018-2815MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.05

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-2798MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-2797MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-2796MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-2795MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-1348MedMar 26, 2018
    risk 0.35cvss 5.3epss 0.01

    NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.

  • CVE-2018-1347MedMar 21, 2018
    risk 0.35cvss 5.3epss 0.01

    The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.

  • CVE-2017-7427MedMar 5, 2018
    risk 0.35cvss 5.4epss 0.01

    Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable application, via user.Context in…

  • CVE-2017-9285MedMar 2, 2018
    risk 0.35cvss 5.4epss 0.01

    NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.

  • CVE-2017-9276MedMar 2, 2018
    risk 0.35cvss 5.4epss 0.01

    Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter.

  • CVE-2017-14802MedMar 2, 2018
    risk 0.35cvss 5.4epss 0.01

    Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.

  • CVE-2017-7426MedMar 1, 2018
    risk 0.35cvss 5.4epss 0.01

    The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks.

  • CVE-2017-14800MedMar 1, 2018
    risk 0.35cvss 5.4epss 0.01

    A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated users.

  • CVE-2017-8993MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found.

  • CVE-2017-8970MedFeb 15, 2018
    risk 0.35cvss 5.3epss 0.02

    A remote unauthenticated disclosure of information vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

  • CVE-2017-8953MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Performance Center version v12.53 and earlier was found.

  • CVE-2017-5827MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A reflected cross site scripting vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

  • CVE-2017-5800MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A Remote Cross-Site Scripting (XSS) vulnerability in HPE Operations Bridge Analytics version v3.0 was found.

  • CVE-2017-5783MedFeb 15, 2018
    risk 0.35cvss 5.3epss 0.02

    A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-5782MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-12544MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.04

    A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2016-8532MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A cross site scripting vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2016-8531MedFeb 15, 2018
    risk 0.35cvss 5.3epss 0.02

    A remote information disclosure vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2016-8522MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

  • CVE-2018-2657MedJan 18, 2018
    risk 0.35cvss 5.3epss 0.06

    Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2018-2629MedJan 18, 2018
    risk 0.35cvss 5.3epss 0.05

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows…

  • CVE-2018-2603MedJan 18, 2018
    risk 0.35cvss 5.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows…

  • CVE-2017-14359MedNov 3, 2017
    risk 0.35cvss 5.4epss 0.01

    A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting.

  • CVE-2017-9273MedOct 6, 2017
    risk 0.35cvss 5.3epss 0.01

    The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes.

  • CVE-2017-13991MedSep 30, 2017
    risk 0.35cvss 5.3epss 0.02

    An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.

  • CVE-2017-13990MedSep 30, 2017
    risk 0.35cvss 5.3epss 0.02

    An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.

  • CVE-2017-7422MedAug 21, 2017
    risk 0.35cvss 5.4epss 0.01

    Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection…

  • CVE-2017-7428MedMay 3, 2017
    risk 0.35cvss 5.3epss 0.01

    NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.

  • CVE-2017-5184MedMar 30, 2017
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).

  • CVE-2016-4393MedOct 28, 2016
    risk 0.35cvss 5.4epss 0.02

    HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.

  • CVE-2016-1598MedOct 27, 2016
    risk 0.35cvss 5.4epss 0.01

    XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.

  • CVE-2016-4380MedSep 8, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in the AdminUI in HPE Operations Manager 9.21.x before 9.21.130 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-2011MedMay 7, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.

  • CVE-2016-2010MedMay 7, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011.

Page 26 of 56