VYPR

Vendor CVEs

Microfocus

All CVEs

2,791 total · sorted by risk
  • CVE-2023-26296HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2022-46359HigJan 30, 2023
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.

  • CVE-2022-46358HigJan 30, 2023
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.

  • CVE-2022-46357HigJan 30, 2023
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.

  • CVE-2022-46356HigJan 30, 2023
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure.

  • CVE-2021-39301HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

  • CVE-2021-39300HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

  • CVE-2021-39299HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

  • CVE-2021-39298HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.

  • CVE-2021-39297HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

  • CVE-2020-28419HigNov 9, 2021
    risk 0.57cvss 8.8epss 0.03

    During installation with certain driver software or application packages an arbitrary code execution could occur.

  • CVE-2021-22517HigAug 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulnerability affects versions 10.10, 10.20, 10.30, 10.40, 10.50, 10.60, 10.70, 10.80, 10.0 and 10.91. A privileged user may potentially misuse this feature and…

  • CVE-2020-7201HigDec 18, 2020
    risk 0.57cvss 8.8epss 0.01

    A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).

  • CVE-2020-7198HigNov 6, 2020
    risk 0.57cvss 8.8epss 0.02

    There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

  • CVE-2020-7195HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A iccselectrules expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7194HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A perfaddormoddevicemonitor expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7193HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7192HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A devicethresholdconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7191HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A devsoftsel expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7190HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A deviceselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7189HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A faultflasheventselectfact expression language injectionremote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7188HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A userselectpagingcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7187HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A reportpage index expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7186HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A powershellconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7185HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A tvxlanlegend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7184HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A viewbatchtaskresultdetailfact expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7183HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A forwardredirect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7182HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A sshconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7181HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A smsrulesdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7180HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A ictexpertdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7179HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A thirdpartyperfselecttask expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7178HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7177HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A wmiconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7176HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A viewtaskresultdetailfact expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7175HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A iccselectdymicparam expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7174HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A soapconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7173HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.03

    A actionselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-24630HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.02

    A remote operatoronlinelist_content privilege escalation vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-11852HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.01

    DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key information to inject system commands into the…

  • CVE-2020-9523HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.01

    Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user…

  • CVE-2020-9521HigMar 26, 2020
    risk 0.57cvss 8.8epss 0.01

    An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead…

  • CVE-2019-11657HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could be exploited to perform CSRF attack.

  • CVE-2019-11655HigOct 4, 2019
    risk 0.57cvss 8.8epss 0.02

    Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.

  • CVE-2019-11666HigSep 17, 2019
    risk 0.57cvss 8.8epss 0.01

    Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data.

  • CVE-2019-5404HigAug 9, 2019
    risk 0.57cvss 8.8epss 0.02

    A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

  • CVE-2019-5395HigAug 9, 2019
    risk 0.57cvss 8.8epss 0.02

    A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2019-11990HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Security vulnerabilities in HPE UIoT versions 1.6, 1.5, 1.4.2, 1.4.1, 1.4.0, and 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: * For customers with release UIoT 1.6, fixes are made available with 1.6 RP603…

  • CVE-2019-6325HigJun 17, 2019
    risk 0.57cvss 8.8epss 0.01

    HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server that is potentially vulnerable to Cross-site Request Forgery.

  • CVE-2019-11986HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.04

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11985HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.04

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Page 9 of 56