← Back

Microfocus

microfocus

273 CVEs • 97 products

Products (97)

Click to collapse
Toggle
Imanager
imanager
Edirectory
edirectory
Filr
filr
Visibroker
visibroker
Sentinel
sentinel
Rumba
rumba
Dimensions Cm
dimensions_cm
Cms Server
cms_server
Groupwise
groupwise
Cobol Server
cobol_server
Visual Cobol
visual_cobol
Cobol
cobol
Accurev
accurev
Rumba Ftp
rumba_ftp
Reflection Zfe
reflection_zfe
Client
client
Universal Cmdb
universal_cmdb
Netware
netware
Acutoweb
acutoweb
Vibe
vibe
Idol
idol
Sitescope
sitescope
Zenworks
zenworks
Vertica
vertica

CVEs (273)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Microfocus
Netiq
2Edirectory
Edirectory
Nov 21, 2024
Mar 2, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
1Microfocus
1Project And Portfolio Management Center
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE)
1Microfocus
1Ucmdb Configuration Manager
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution.
1Microfocus
1Universal Cmdb Foundation Software
Jun 17, 2026
Feb 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow dis...Show more
Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information.Show less
1Microfocus
1Project And Portfolio Management
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found.
1Microfocus
2Fortify Audit Workbench
Fortify Software Security Center
Jun 17, 2026
Feb 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a...Show more
XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.Show less
1Microfocus
1Operations Manager I
May 13, 2026
Dec 21, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
1Microfocus
1Project And Portfolio Management
May 13, 2026
Dec 13, 2017
N/A· v4
7.3 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Cross-Site Forgery attack.
1Microfocus
1Project And Portfolio Management
May 13, 2026
Dec 13, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Man-In-The-Middle vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Man-in-the-middle attack.
1Microfocus
1Connected Backup
May 13, 2026
Dec 5, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability could be exploited locally to allow escalation of privilege.
1Microfocus
1Bi Directional Driver
May 13, 2026
Oct 6, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes.
1Microfocus
1Bi Directional Driver
May 13, 2026
Oct 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.
1Microfocus
1Visibroker
May 13, 2026
Sep 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.
1Microfocus
1Visibroker
May 13, 2026
Sep 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corruption in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attac...Show more
An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corruption in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.Show less
1Microfocus
1Visibroker
May 13, 2026
Sep 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An integer overflow (CWE-190) potentially causing an out-of-bounds read (CWE-125) vulnerability in Micro Focus VisiBroker 8.5 can lead to a denial of service.
1Microfocus
2Enterprise Developer
Enterprise Server
May 13, 2026
Aug 21, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to do...Show more
A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to download arbitrary files from a system running the product, if this component is configured. Note esfadmingui is not enabled by default.Show less
1Microfocus
2Enterprise Developer
Enterprise Server
May 13, 2026
Aug 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthentica...Show more
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is configured. This includes creating new privileged credentials, resulting in privilege elevation (CWE-275). Note esfadmingui is not enabled by default.Show less
1Microfocus
2Enterprise Developer
Enterprise Server
May 13, 2026
Aug 21, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow r...Show more
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features, if this component is configured. Note esfadmingui is not enabled by default.Show less
1Microfocus
4Directory Server
Enterprise DeveloperEnterprise Server+1 more
May 13, 2026
Aug 21, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise De...Show more
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features.Show less
1Microfocus
3Enterprise Developer
Enterprise ServerEnterprise Server Monitor And Control
May 13, 2026
Aug 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Updat...Show more
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration information and alter the state of the running product (CWE-275).Show less