Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Microfocus Subscribe
Total 209 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-6946 1 Microfocus 1 Accurev 2019-06-26 9.3 HIGH N/A
Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary code via the (1) akey or (2) actserver parameter to the activate_doit function or (3) licfile parameter to the service_startup_doit functionality.
CVE-2019-3477 1 Microfocus 1 Solutions Business Manager 2019-06-10 5.8 MEDIUM 6.1 MEDIUM
Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.
CVE-2016-1600 1 Microfocus 1 Identity Manager 2019-05-10 5.0 MEDIUM 7.5 HIGH
The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.
CVE-2019-3490 1 Microfocus 1 Open Enterprise Server 2019-05-06 4.3 MEDIUM 6.1 MEDIUM
A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.
CVE-2019-3489 1 Microfocus 1 Content Manager 2019-04-02 5.0 MEDIUM 7.5 HIGH
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the Content Manager server.
CVE-2016-9166 1 Microfocus 1 Netiq Edirectory 2019-03-27 5.0 MEDIUM 7.5 HIGH
NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.
CVE-2017-5185 1 Microfocus 1 Sentinel 2019-03-19 5.0 MEDIUM 7.5 HIGH
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.
CVE-2017-5184 1 Microfocus 1 Sentinel 2019-03-19 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).
CVE-2018-19645 1 Microfocus 1 Solutions Business Manager 2019-02-13 7.5 HIGH 9.8 CRITICAL
An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
CVE-2018-17949 1 Microfocus 1 Imanager 2019-01-02 4.3 MEDIUM 6.1 MEDIUM
Cross site scripting vulnerability in iManager prior to 3.1 SP2.
CVE-2018-17952 1 Microfocus 1 Edirectory 2018-12-31 4.3 MEDIUM 6.1 MEDIUM
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
CVE-2018-12480 1 Microfocus 1 Access Manager 2018-12-27 4.3 MEDIUM 6.1 MEDIUM
Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.
CVE-2018-17948 1 Microfocus 1 Access Manager 2018-12-26 5.8 MEDIUM 6.1 MEDIUM
An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
CVE-2009-5153 1 Microfocus 1 Netware 2018-12-19 7.5 HIGH 9.8 CRITICAL
In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote unauthenticated attackers to execute code, because a length field was incorrectly trusted.
CVE-2016-1991 1 Microfocus 1 Arcsight Enterprise Security Manager 2018-10-17 6.0 MEDIUM 8.0 HIGH
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download" attacks via unknown vectors.
CVE-2015-6030 2 Hp, Microfocus 7 Arcsight Command Center, Arcsight Connector Appliance, Arcsight Connectors and 4 more 2018-10-17 7.2 HIGH N/A
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
CVE-2016-1990 1 Microfocus 1 Arcsight Enterprise Security Manager 2018-10-17 4.3 MEDIUM 7.8 HIGH
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.
CVE-2018-6489 1 Microfocus 1 Project And Portfolio Management Center 2018-03-20 7.5 HIGH 9.8 CRITICAL
XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE)
CVE-2017-8993 1 Microfocus 1 Project And Portfolio Management 2018-03-12 3.5 LOW 5.4 MEDIUM
A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found.
CVE-2017-9272 1 Microfocus 2 Bi-directional Driver, Identity Manager 2017-10-20 5.0 MEDIUM 7.5 HIGH
The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.