VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2021-29210MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity…

  • CVE-2021-29209MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity…

  • CVE-2021-29208MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity…

  • CVE-2021-29207MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29206MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29205MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29204MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29201MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2019-18946MedFeb 26, 2021
    risk 0.31cvss 4.8epss 0.00

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.

  • CVE-2021-22499MedFeb 6, 2021
    risk 0.31cvss 4.8epss 0.01

    Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow persistent XSS attack.

  • CVE-2020-25833MedNov 17, 2020
    risk 0.31cvss 4.8epss 0.01

    Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. The vulnerability could be exploited to perform Persistent XSS attack.

  • CVE-2019-6332MedJan 9, 2020
    risk 0.31cvss 4.8epss 0.01

    A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A -…

  • CVE-2019-5403MedAug 9, 2019
    risk 0.31cvss 4.8epss 0.01

    A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

  • CVE-2019-5401MedAug 1, 2019
    risk 0.31cvss 4.8epss 0.01

    A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are…

  • CVE-2019-2816MedJul 23, 2019
    risk 0.31cvss 4.8epss 0.02

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker…

  • CVE-2019-6324MedJun 17, 2019
    risk 0.31cvss 4.8epss 0.01

    HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to stored XSS in wireless configuration page

  • CVE-2018-19643MedMar 27, 2019
    risk 0.31cvss 4.7epss 0.01

    Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

  • CVE-2018-12462MedJul 10, 2018
    risk 0.31cvss 4.8epss 0.01

    NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.

  • CVE-2018-7681MedJun 21, 2018
    risk 0.31cvss 4.8epss 0.01

    Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system.

  • CVE-2018-6492MedMay 22, 2018
    risk 0.31cvss 4.7epss 0.01

    Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited…

  • CVE-2017-9284MedApr 26, 2018
    risk 0.31cvss 4.8epss 0.01

    IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.

  • CVE-2023-1526MedApr 28, 2023
    risk 0.30cvss 4.6epss 0.01

    Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer.

  • CVE-2021-39237MedNov 3, 2021
    risk 0.30cvss 4.6epss 0.02

    Certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers may be vulnerable to potential information disclosure.

  • CVE-2019-16285MedNov 22, 2019
    risk 0.30cvss 4.6epss 0.01

    If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extract sensitive information onto a local drive.

  • CVE-2019-3486MedJul 25, 2019
    risk 0.30cvss 4.6epss 0.01

    Mitigates a stored cross site scripting issue in ArcSight Security Management Center versions prior to 2.9.1

  • CVE-2019-3485MedJul 24, 2019
    risk 0.30cvss 4.6epss 0.01

    Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1

  • CVE-2017-2751MedOct 3, 2018
    risk 0.30cvss 4.6epss 0.01

    A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

  • CVE-2017-7437MedMar 5, 2018
    risk 0.30cvss 4.6epss 0.01

    NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.

  • CVE-2017-7438MedMar 2, 2018
    risk 0.30cvss 4.6epss 0.01

    NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter.

  • CVE-2017-7419MedMar 2, 2018
    risk 0.30cvss 4.6epss 0.01

    A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.

  • CVE-2017-14801MedMar 2, 2018
    risk 0.30cvss 4.6epss 0.01

    Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.

  • CVE-2017-14799MedMar 1, 2018
    risk 0.30cvss 4.6epss 0.01

    A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript code into the login page.

  • CVE-2017-8978MedFeb 15, 2018
    risk 0.30cvss 4.6epss 0.01

    A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.

  • CVE-2025-43485MedJul 23, 2025
    risk 0.29cvss 4.5epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the latest software update.

  • CVE-2018-2799MedApr 19, 2018
    risk 0.29cvss 5.3epss 0.15

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated…

  • CVE-2017-8974MedFeb 15, 2018
    risk 0.29cvss 4.4epss 0.01

    A Local Authentication Restriction Bypass vulnerability in HPE NonStop Server version L-Series: T6533L01 through T6533L01^ADN; J-Series and H-series: T6533H02 through T6533H04^ADF and T6533H05 through T6533H05^ADL was found.

  • CVE-2018-2602MedJan 18, 2018
    risk 0.29cvss 4.5epss 0.01

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with…

  • CVE-2016-4381MedSep 8, 2016
    risk 0.29cvss 4.5epss 0.00

    HPE XP7 Command View Advanced Edition (CVAE) Suite 6.x through 8.x before 8.4.1-02, when Replication Manager (RepMgr) and Device Manager (DevMgr) are enabled, allows local users to bypass intended access restrictions via unspecified vectors.

  • CVE-1999-0524MedAug 1, 1997
    risk 0.29cvss 4.0epss 0.32

    ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

  • CVE-2024-0967MedMar 1, 2024
    risk 0.28cvss 4.3epss 0.01

    A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.

  • CVE-2023-4468MedDec 29, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack…

  • CVE-2023-45627MedNov 14, 2023
    risk 0.28cvss 4.3epss 0.01

    An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

  • CVE-2023-32262MedJul 19, 2023
    risk 0.28cvss 4.3epss 0.01

    A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Item/Configure permission to access and capture credentials they are not entitled to. See the following Jenkins security advisory for…

  • CVE-2022-38756MedDec 16, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.

  • CVE-2020-11841MedJun 16, 2020
    risk 0.28cvss 4.3epss 0.01

    Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure.

  • CVE-2020-11840MedJun 16, 2020
    risk 0.28cvss 4.3epss 0.01

    Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure.

  • CVE-2019-11662MedSep 18, 2019
    risk 0.28cvss 4.3epss 0.01

    Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited in some special cases to allow information exposure through an error…

  • CVE-2019-11658MedAug 30, 2019
    risk 0.28cvss 4.3epss 0.01

    Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access when the system is in…

  • CVE-2019-5393MedJun 5, 2019
    risk 0.28cvss 4.3epss 0.02

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-7317MedFeb 4, 2019
    risk 0.28cvss 5.3epss 0.09

    png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Page 28 of 56