VYPR

Vendor CVEs

Microfocus

All CVEs

2,781 total · sorted by risk
  • CVE-2020-24651CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A syslogtempletselectwin expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-24650CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-24649CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.04

    A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-24647CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.04

    A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-24646CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A tftpserver stack-based buffer overflow remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-24629CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.03

    A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-11856CriSep 22, 2020
    risk 0.64cvss 9.8epss 0.05

    Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.

  • CVE-2020-11849CriJul 8, 2020
    risk 0.64cvss 9.8epss 0.01

    Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an unauthorized access.

  • CVE-2020-7133CriApr 24, 2020
    risk 0.64cvss 9.8epss 0.02

    A unauthorized remote access vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.

  • CVE-2014-2228CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.03

    The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.

  • CVE-2019-6330CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.02

    A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege.

  • CVE-2019-11994CriJan 3, 2020
    risk 0.64cvss 9.8epss 0.07

    A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell…

  • CVE-2019-10627CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.01

    Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF…

  • CVE-2019-6334CriOct 16, 2019
    risk 0.64cvss 9.8epss 0.04

    HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signature that may allow potential execution of arbitrary code.

  • CVE-2019-11652CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate.

  • CVE-2019-11991CriJul 9, 2019
    risk 0.64cvss 9.8epss 0.05

    HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and…

  • CVE-2019-6327CriJun 17, 2019
    risk 0.64cvss 9.8epss 0.02

    HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an IPP Parser potentially vulnerable to Buffer Overflow.

  • CVE-2019-11949CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.08

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-5391CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.03

    A stack buffer overflow vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-5390CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.04

    A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-5387CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.08

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-5367CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.08

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-5358CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.08

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-5352CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.08

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-5347CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.05

    A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2018-7124CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.08

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2018-7121CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.08

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2018-7120CriMay 10, 2019
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability in the HPE Virtual Connect SE 16Gb Fibre Channel Module for HPE Synergy running firmware 5.00.50, which is part of the HPE Synergy Custom SPP 2018.11.20190205, could allow local or remote unauthorized elevation of privilege.

  • CVE-2019-6318CriApr 11, 2019
    risk 0.64cvss 9.8epss 0.03

    HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code.

  • CVE-2018-5923CriMar 27, 2019
    risk 0.64cvss 9.8epss 0.03

    In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.

  • CVE-2019-3479CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.07

    Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.

  • CVE-2019-3476CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.03

    Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.

  • CVE-2018-19645CriFeb 12, 2019
    risk 0.64cvss 9.8epss 0.01

    An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

  • CVE-2009-5153CriNov 21, 2018
    risk 0.64cvss 9.8epss 0.06

    In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote unauthenticated attackers to execute code, because a length field was incorrectly trusted.

  • CVE-2018-7104CriSep 27, 2018
    risk 0.64cvss 9.8epss 0.09

    A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than version IMC WSM 7.3 E0506P02.

  • CVE-2018-7103CriSep 27, 2018
    risk 0.64cvss 9.8epss 0.09

    A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier than version IMC WSM 7.3 E0506P02.

  • CVE-2018-7096CriAug 14, 2018
    risk 0.64cvss 9.8epss 0.03

    A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow code execution.

  • CVE-2018-7095CriAug 14, 2018
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow access restriction bypass.

  • CVE-2018-7072CriAug 6, 2018
    risk 0.64cvss 9.8epss 0.03

    A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

  • CVE-2018-7058CriAug 6, 2018
    risk 0.64cvss 9.8epss 0.04

    Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including…

  • CVE-2017-9000CriAug 6, 2018
    risk 0.64cvss 9.8epss 0.06

    ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x prior to 8.1.0.4 FIPS and non-FIPS versions of software are both affected equally is vulnerable to unauthenticated arbitrary file…

  • CVE-2017-8992CriAug 6, 2018
    risk 0.64cvss 9.8epss 0.03

    HPE has identified a remote privilege escalation vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

  • CVE-2017-8988CriAug 6, 2018
    risk 0.64cvss 9.8epss 0.03

    A Remote Bypass of Security Restrictions vulnerability was identified in HPE XP Command View Advanced Edition Software Earlier than 8.5.3-00. The vulnerability impacts DevMgr Earlier than 8.5.3-00 (for Windows, Linux), RepMgr earlier than 8.5.3-00 (for Windows, Linux) and HDLM…

  • CVE-2018-7679CriJun 21, 2018
    risk 0.64cvss 9.8epss 0.02

    Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.

  • CVE-2018-9029CriJun 18, 2018
    risk 0.64cvss 9.8epss 0.02

    An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.

  • CVE-2018-1343CriMar 6, 2018
    risk 0.64cvss 9.8epss 0.01

    PAM exposure enabling unauthenticated access to remote host

  • CVE-2018-6489CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE)

  • CVE-2018-6487CriFeb 20, 2018
    risk 0.64cvss 9.8epss 0.02

    Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information.

  • CVE-2017-8981CriFeb 15, 2018
    risk 0.64cvss 9.8epss 0.09

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.

  • CVE-2017-8979CriFeb 15, 2018
    risk 0.64cvss 9.8epss 0.05

    Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code execution, and denial of service.

Page 5 of 56