← Back

Microfocus

microfocus

273 CVEs • 97 products

Products (97)

Click to collapse
Toggle
Imanager
imanager
Edirectory
edirectory
Filr
filr
Visibroker
visibroker
Sentinel
sentinel
Rumba
rumba
Dimensions Cm
dimensions_cm
Cms Server
cms_server
Groupwise
groupwise
Cobol Server
cobol_server
Visual Cobol
visual_cobol
Cobol
cobol
Accurev
accurev
Rumba Ftp
rumba_ftp
Reflection Zfe
reflection_zfe
Client
client
Universal Cmdb
universal_cmdb
Netware
netware
Acutoweb
acutoweb
Vibe
vibe
Idol
idol
Sitescope
sitescope
Zenworks
zenworks
Vertica
vertica

CVEs (273)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microfocus
1Security Manager
May 6, 2026
Jul 7, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager through 6.5.4 allows remote attackers to execute arbitrary code via unspecified vectors, a different...Show more
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager through 6.5.4 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3460.Show less
1Microfocus
2Sentinel
Sentinel Agent Manager
May 6, 2026
May 20, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attackers to create arbitrary files, and consequently execute arbitrary code,...Show more
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted pathname.Show less
1Microfocus
1Arcsight Enterprise Security Manager
Apr 29, 2026
Sep 20, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the web interface in HP ArcSight Enterprise Security Manager (ESM) before 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Microfocus
1Edirectory
Apr 29, 2026
Dec 25, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.
1Microfocus
1Edirectory
Apr 29, 2026
Dec 25, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors.
1Microfocus
1Edirectory
Apr 29, 2026
Dec 25, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request.
1Microfocus
1Edirectory
Apr 29, 2026
Dec 25, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Microfocus
1Privileged User Manager
Apr 29, 2026
Dec 24, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute arbitrary Perl code via a crafted applic...Show more
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute arbitrary Perl code via a crafted application/x-amf request.Show less
1Microfocus
1Privileged User Manager
Apr 29, 2026
Dec 24, 2012
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote authenticated users to create or overwrite arbitrary fil...Show more
Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote authenticated users to create or overwrite arbitrary files via directory traversal sequences in a log pathname.Show less
1Microfocus
1Privileged User Manager
Apr 29, 2026
Dec 24, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the...Show more
The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the passwords of administrative accounts via a crafted application/x-amf request.Show less
1Microfocus
1Visibroker
Apr 23, 2026
Aug 31, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet with a large string length value to UDP port 14000, which trigger...Show more
osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet with a large string length value to UDP port 14000, which triggers a memory allocation failure that is not properly handled.Show less
1Microfocus
1Visibroker
Apr 23, 2026
Aug 31, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a la...Show more
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a large string length value to UDP port 14000, which triggers a heap-based buffer overflow.Show less
1Microfocus
1Cobol
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.