Vendor CVEs
Microfocus
All CVEs
2,790 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-7071 | Med | 0.28 | 4.3 | 0.01 | Aug 6, 2018 | HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3. | ||
| CVE-2018-2940 | Med | 0.28 | 4.3 | 0.03 | Jul 18, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with… | ||
| CVE-2018-2800 | Med | 0.28 | 4.2 | 0.06 | Apr 19, 2018 | Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple… | ||
| CVE-2017-9280 | Med | 0.28 | 4.3 | 0.01 | Mar 2, 2018 | Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar. | ||
| CVE-2017-5189 | Med | 0.28 | 4.3 | 0.01 | Mar 2, 2018 | NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance. | ||
| CVE-2017-8973 | Med | 0.28 | 4.3 | 0.01 | Feb 15, 2018 | An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | ||
| CVE-2017-8972 | Med | 0.28 | 4.3 | 0.01 | Feb 15, 2018 | A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | ||
| CVE-2017-8971 | Med | 0.28 | 4.3 | 0.01 | Feb 15, 2018 | A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | ||
| CVE-2018-2678 | Med | 0.28 | 4.3 | 0.05 | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows… | ||
| CVE-2018-2677 | Med | 0.28 | 4.3 | 0.05 | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network… | ||
| CVE-2018-2663 | Med | 0.28 | 4.3 | 0.05 | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows… | ||
| CVE-2018-2588 | Med | 0.28 | 4.3 | 0.03 | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low… | ||
| CVE-2023-32261 | Med | 0.27 | 4.2 | 0.01 | Jul 19, 2023 | A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. See the following Jenkins security advisory for… | ||
| CVE-2022-26326 | Med | 0.26 | 4.0 | 0.00 | May 2, 2022 | Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2 | ||
| CVE-2021-22497 | Low | 0.25 | 3.8 | 0.01 | Apr 12, 2021 | Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue. | ||
| CVE-2018-15532 | Low | 0.25 | 3.8 | 0.01 | Mar 21, 2019 | SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses. | ||
| CVE-2018-7676 | Low | 0.25 | 3.9 | 0.01 | Mar 28, 2018 | The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information. | ||
| CVE-2019-2842 | Low | 0.24 | 3.7 | 0.03 | Jul 23, 2019 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JCE). The supported version that is affected is Java SE: 8u212. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful… | ||
| CVE-2019-2426 | Low | 0.24 | 3.7 | 0.03 | Jan 16, 2019 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via… | ||
| CVE-2018-2952 | Low | 0.24 | 3.7 | 0.04 | Jul 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability… | ||
| CVE-2018-2579 | Low | 0.24 | 3.7 | 0.04 | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows… | ||
| CVE-2016-4379 | Low | 0.24 | 3.7 | 0.02 | Sep 8, 2016 | The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay… | ||
| CVE-2015-6858 | Low | 0.24 | 3.7 | 0.03 | Jan 5, 2016 | HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors. | ||
| CVE-2024-3487 | Low | 0.23 | 3.5 | 0.00 | May 15, 2024 | Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication. | ||
| CVE-2019-18947 | Low | 0.23 | 3.5 | 0.00 | Feb 26, 2021 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure. | ||
| CVE-2018-12461 | Low | 0.23 | 3.5 | 0.00 | Jul 10, 2018 | Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation. | ||
| CVE-2018-7678 | Low | 0.23 | 3.5 | 0.01 | Mar 14, 2018 | A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4. | ||
| CVE-2018-7677 | Low | 0.23 | 3.5 | 0.01 | Mar 14, 2018 | A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component. | ||
| CVE-2016-8535 | Low | 0.23 | 3.5 | 0.01 | Feb 15, 2018 | A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found. | ||
| CVE-2019-2786 | Low | 0.22 | 3.4 | 0.03 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with… | ||
| CVE-2018-3136 | Low | 0.22 | 3.4 | 0.05 | Oct 17, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with… | ||
| CVE-2017-9278 | Low | 0.22 | 3.3 | 0.01 | Mar 2, 2018 | The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables. | ||
| CVE-2017-7434 | Low | 0.22 | 3.3 | 0.01 | Mar 2, 2018 | In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles. | ||
| CVE-2023-5449 | Low | 0.21 | 3.3 | 0.00 | Oct 13, 2023 | A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature which may allow a monitor’s Theft Deterrence to be deactivated. | ||
| CVE-2021-38129 | Low | 0.21 | 3.3 | 0.00 | Jan 25, 2022 | Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and including 12.21. The vulnerability could be exploited by a non-privileged local user to access system monitoring data collected by Operations Agent. | ||
| CVE-2010-3282 | Low | 0.21 | 3.3 | 0.00 | Jan 9, 2020 | 389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local… | ||
| CVE-2019-6331 | Low | 0.21 | 3.3 | 0.00 | Jan 9, 2020 | An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information. | ||
| CVE-2018-3139 | Low | 0.21 | 3.1 | 0.05 | Oct 17, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with… | ||
| CVE-2018-2790 | Low | 0.21 | 3.1 | 0.05 | Apr 19, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with… | ||
| CVE-2019-2766 | Low | 0.20 | 3.1 | 0.03 | Jul 23, 2019 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker… | ||
| CVE-2019-2422 | Low | 0.20 | 3.1 | 0.03 | Jan 16, 2019 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via… | ||
| CVE-2018-1346 | Low | 0.20 | 3.1 | 0.01 | Mar 21, 2018 | Addresses denial of service attack to eDirectory versions prior to 9.1. | ||
| CVE-2018-1344 | Low | 0.20 | 3.1 | 0.01 | Mar 21, 2018 | Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1 | ||
| CVE-2017-5190 | Low | 0.20 | 3.1 | 0.01 | Apr 20, 2017 | NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile. | ||
| CVE-2022-26325 | Low | 0.19 | 2.9 | 0.00 | May 2, 2022 | Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2 | ||
| CVE-2017-9275 | Low | 0.18 | 2.8 | 0.01 | Apr 26, 2018 | NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack. | ||
| CVE-2018-7675 | Low | 0.18 | 2.8 | 0.01 | Mar 7, 2018 | In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes the interface to timeout so that it requires the user to… | ||
| CVE-2023-32263 | Low | 0.17 | 2.6 | 0.00 | Jul 19, 2023 | A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability… | ||
| CVE-2024-4692 | Low | 0.16 | 2.4 | 0.00 | Oct 16, 2024 | Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in… | ||
| CVE-2024-4211 | Low | 0.16 | 2.4 | 0.00 | Oct 16, 2024 | Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText… |
- risk 0.28cvss 4.3epss 0.01
HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3.
- risk 0.28cvss 4.3epss 0.03
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with…
- risk 0.28cvss 4.2epss 0.06
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple…
- risk 0.28cvss 4.3epss 0.01
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
- risk 0.28cvss 4.3epss 0.01
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
- risk 0.28cvss 4.3epss 0.01
An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
- risk 0.28cvss 4.3epss 0.01
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
- risk 0.28cvss 4.3epss 0.01
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
- risk 0.28cvss 4.3epss 0.05
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows…
- risk 0.28cvss 4.3epss 0.05
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network…
- risk 0.28cvss 4.3epss 0.05
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows…
- risk 0.28cvss 4.3epss 0.03
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low…
- risk 0.27cvss 4.2epss 0.01
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. See the following Jenkins security advisory for…
- risk 0.26cvss 4.0epss 0.00
Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2
- risk 0.25cvss 3.8epss 0.01
Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.
- risk 0.25cvss 3.8epss 0.01
SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses.
- risk 0.25cvss 3.9epss 0.01
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
- risk 0.24cvss 3.7epss 0.03
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JCE). The supported version that is affected is Java SE: 8u212. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful…
- risk 0.24cvss 3.7epss 0.03
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via…
- risk 0.24cvss 3.7epss 0.04
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability…
- risk 0.24cvss 3.7epss 0.04
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows…
- risk 0.24cvss 3.7epss 0.02
The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay…
- risk 0.24cvss 3.7epss 0.03
HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors.
- risk 0.23cvss 3.5epss 0.00
Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.
- risk 0.23cvss 3.5epss 0.00
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.
- risk 0.23cvss 3.5epss 0.00
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
- risk 0.23cvss 3.5epss 0.01
A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4.
- risk 0.23cvss 3.5epss 0.01
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
- risk 0.23cvss 3.5epss 0.01
A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.
- risk 0.22cvss 3.4epss 0.03
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with…
- risk 0.22cvss 3.4epss 0.05
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with…
- risk 0.22cvss 3.3epss 0.01
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
- risk 0.22cvss 3.3epss 0.01
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
- risk 0.21cvss 3.3epss 0.00
A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature which may allow a monitor’s Theft Deterrence to be deactivated.
- risk 0.21cvss 3.3epss 0.00
Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and including 12.21. The vulnerability could be exploited by a non-privileged local user to access system monitoring data collected by Operations Agent.
- risk 0.21cvss 3.3epss 0.00
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local…
- risk 0.21cvss 3.3epss 0.00
An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information.
- risk 0.21cvss 3.1epss 0.05
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with…
- risk 0.21cvss 3.1epss 0.05
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with…
- risk 0.20cvss 3.1epss 0.03
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker…
- risk 0.20cvss 3.1epss 0.03
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via…
- risk 0.20cvss 3.1epss 0.01
Addresses denial of service attack to eDirectory versions prior to 9.1.
- risk 0.20cvss 3.1epss 0.01
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
- risk 0.20cvss 3.1epss 0.01
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.
- risk 0.19cvss 2.9epss 0.00
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2
- risk 0.18cvss 2.8epss 0.01
NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack.
- risk 0.18cvss 2.8epss 0.01
In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes the interface to timeout so that it requires the user to…
- risk 0.17cvss 2.6epss 0.00
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability…
- risk 0.16cvss 2.4epss 0.00
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in…
- risk 0.16cvss 2.4epss 0.00
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText…
Page 29 of 56