← Back

Microfocus

microfocus

273 CVEs • 97 products

Products (97)

Click to collapse
Toggle
Imanager
imanager
Edirectory
edirectory
Filr
filr
Visibroker
visibroker
Sentinel
sentinel
Rumba
rumba
Dimensions Cm
dimensions_cm
Cms Server
cms_server
Groupwise
groupwise
Cobol Server
cobol_server
Visual Cobol
visual_cobol
Cobol
cobol
Accurev
accurev
Rumba Ftp
rumba_ftp
Reflection Zfe
reflection_zfe
Client
client
Universal Cmdb
universal_cmdb
Netware
netware
Acutoweb
acutoweb
Vibe
vibe
Idol
idol
Sitescope
sitescope
Zenworks
zenworks
Vertica
vertica

CVEs (273)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microfocus
1Access Manager
Jun 29, 2026
Jun 24, 2026
8.2 HIGH· v4
6.1 MEDIUM· v3
N/A· v2
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.
1Microfocus
1Access Manager
Jun 29, 2026
Jun 24, 2026
6.3 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.
1Microfocus
1Operations Agent
Jul 24, 2026
Mar 31, 2026
8.6 HIGH· v4
7.8 HIGH· v3
N/A· v2
A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manu...Show more
A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerabilityShow less
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5
1Microfocus
2Arcsight Management Center
Arcsight Platform
Jun 17, 2026
Nov 8, 2024
7.0 HIGH· v4
6.1 MEDIUM· v3
N/A· v2
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.
1Microfocus
1Imanager
Jun 17, 2026
Nov 6, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3
1Microfocus
1Operations Agent
Jun 17, 2026
Oct 28, 2024
1.8 LOW· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an attacker with local admin permissions to man...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system. This issue affects Operations Agent: 12.20, 12.21, 12.22, 12.23, 12.24, 12.25, 12.26.Show less
1Microfocus
1Application Automation Tools
Jun 17, 2026
Oct 16, 2024
1.8 LOW· v4
2.4 LOW· v3
N/A· v2
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission ch...Show more
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate Service Virtualization server names. This issue affects OpenText Application Automation Tools: 24.1.0 and below.Show less
1Microfocus
1Application Automation Tools
Jun 17, 2026
Oct 16, 2024
5.1 MEDIUM· v4
8.0 HIGH· v3
N/A· v2
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
1Microfocus
1Application Automation Tools
Jun 17, 2026
Oct 16, 2024
1.8 LOW· v4
2.4 LOW· v3
N/A· v2
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission ch...Show more
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate ALM server names, usernames and client IDs configured to be used with ALM servers. This issue affects OpenText Application Automation Tools: 24.1.0 and below.Show less
1Microfocus
1Application Automation Tools
Jun 17, 2026
Oct 16, 2024
5.9 MEDIUM· v4
8.0 HIGH· v3
N/A· v2
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
1Microfocus
1Application Automation Tools
Jun 17, 2026
Oct 16, 2024
5.9 MEDIUM· v4
8.0 HIGH· v3
N/A· v2
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.