← Back

Microfocus

microfocus

273 CVEs • 97 products

Products (97)

Click to collapse
Toggle
Imanager
imanager
Edirectory
edirectory
Filr
filr
Visibroker
visibroker
Sentinel
sentinel
Rumba
rumba
Dimensions Cm
dimensions_cm
Cms Server
cms_server
Groupwise
groupwise
Cobol Server
cobol_server
Visual Cobol
visual_cobol
Cobol
cobol
Accurev
accurev
Rumba Ftp
rumba_ftp
Reflection Zfe
reflection_zfe
Client
client
Universal Cmdb
universal_cmdb
Netware
netware
Acutoweb
acutoweb
Vibe
vibe
Idol
idol
Sitescope
sitescope
Zenworks
zenworks
Vertica
vertica

CVEs (273)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microfocus
8Data Center Automation
Hybrid Cloud ManagementNetwork Operations Management+5 more
Jun 17, 2026
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Cont...Show more
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05, Service Virtualization (SV) with floating licenses using Any version using APLS older than 10.7, Unified Functional Testing (UFT) with floating licenses using Any version using APLS older than 10.7, Network Virtualization (NV) with floating licenses using Any version using APLS older than 10.7 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.Show less
1Microfocus
5Data Center Automation
Hybrid Cloud ManagementNetwork Operations Management+2 more
Jun 17, 2026
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Cont...Show more
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.Show less
1Microfocus
1Edirectory
Jun 17, 2026
Aug 9, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.
1Microfocus
1Edirectory
Jun 17, 2026
Aug 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.
1Microfocus
1Groupwise
Nov 21, 2024
Aug 1, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server. In certain...Show more
A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server. In certain circumstances this could result in remote code execution.Show less
1Microfocus
1Secure Messaging Gateway
Nov 21, 2024
Jun 29, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the...Show more
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).Show less
1Microfocus
1Secure Messaging Gateway
Nov 21, 2024
Jun 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database...Show more
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with CVE-2018-12465 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that use the GWAVA product name (i.e. GWAVA 6.5).Show less
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 21, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact ot...Show more
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system.Show less
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 21, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Jun 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote c...Show more
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.Show less
1Microfocus
2Cms Server
Universal Cmbd Server
Jun 17, 2026
Jun 16, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018....Show more
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).Show less
1Microfocus
1Universal Cmbd Browser
Jun 17, 2026
Jun 16, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forger...Show more
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).Show less
1Microfocus
3Cms Server
Universal CmdbUniversal Cmdb Browser
Jun 17, 2026
May 23, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11...Show more
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).Show less
1Microfocus
1Service Manager
Jun 17, 2026
May 22, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
1Microfocus
1Client
Jun 17, 2026
May 21, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevate privileges via a buffer overflow in ncfsd.sys.
1Microfocus
1Ucmdb Configuration Manager
Jun 17, 2026
Apr 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.2 HIGH· v2
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.
1Microfocus
1Sentinel
Jun 17, 2026
Mar 7, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes...Show more
In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes the interface to timeout so that it requires the user to re-authenticate. If another user is passing by and decides to login, their credentials are accepted. While The user does not inherit any of the other users privileges, they are able to view the previous screen. In this case it is possible that the user can see another users events or configuration information for whatever view is currently showing.Show less
2Microfocus
Netiq
2Edirectory
Edirectory
Nov 21, 2024
Mar 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.