microfocus records
276 published records for vendor microfocus.
Researcher profile
- Entered KEV
- 2 · 0.7%
- Weaponized
- 13 · 4.7%
- Pre-auth RCE
- 35
- With a fix record
- 12%
- Median publish → KEV
- 245 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')56
- CWE-611 Improper Restriction of XML External Entity Reference13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-20 Improper Input Validation8
The weakness classes this vendor ships most often: where to look.
CWEAll records
276 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2021-22502Weaponized | Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40.microfocus · operation bridge reporter · CWE-78 | Critical9.8 | KEV | 96.7% | Feb 8, 2021 |
68This week | CVE-2021-22506Weaponized | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to versiomicrofocus · access manager | High7.5 | KEV | 25.7% | Mar 26, 2021 |
64This week | CVE-2019-5736Weaponized | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | High8.6 | — | 98.5% | Feb 11, 2019 |
63This week | CVE-2018-12464Weaponized | Unauthenticated SQL injection in Micro Focus Secure Messaging Gatewaymicrofocus · secure messaging gateway · CWE-89 | Critical9.8 | — | 80.7% | Jun 29, 2018 |
61This week | CVE-2020-11854Weaponized | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.microfocus · application performance management · CWE-798 | Critical9.8 | — | 74.4% | Oct 27, 2020 |
59Plan | CVE-2012-5932Weaponized | Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1microfocus · privileged user manager · CWE-94 | Critical10.0 | — | 62.8% | Dec 24, 2012 |
58Plan | CVE-2020-11853Weaponized | Arbitrary code execution vulnerability on multiple Micro Focus productsmicrofocus · operation bridge manager | High8.8 | — | 77.0% | Oct 22, 2020 |
58Plan | CVE-2012-0432Weaponized | Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an umicrofocus · edirectory · CWE-119 | Critical10.0 | — | 58.7% | Dec 25, 2012 |
53Plan | CVE-2016-1606Proof of concept | Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrmicrofocus · rumba · CWE-119 | Critical9.8 | — | 45.6% | Jul 2, 2016 |
52Plan | CVE-2018-12465Weaponized | Remote Code Execution in Micro Focus Secure Messaging Gatewaymicrofocus · secure messaging gateway · CWE-77 | High7.2 | — | 80.0% | Jun 29, 2018 |
44Plan | CVE-2020-11857Weaponized | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.microfocus · operation bridge reporter · CWE-798 | Critical9.8 | — | 15.8% | Sep 22, 2020 |
44Plan | CVE-2016-5228Proof of concept | Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11microfocus · rumba · CWE-119 | Critical9.8 | — | 15.1% | Jul 2, 2016 |
43Plan | CVE-2015-6946No exploit | Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary microfocus · accurev · CWE-119 | Critical9.3 | — | 21.2% | Sep 15, 2015 |
43Plan | CVE-2008-7126Proof of concept | Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of semicrofocus · visibroker · CWE-189 | Critical10.0 | — | 10.0% | Aug 31, 2009 |
41Plan | CVE-2009-5153No exploit | In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allomicrofocus · netware · CWE-119 | Critical9.8 | — | 6.1% | Nov 21, 2018 |
41Plan | CVE-2020-11856No exploit | Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.microfocus · operation bridge reporter · CWE-306 | Critical9.8 | — | 5.2% | Sep 22, 2020 |
41Plan | CVE-2014-7885No exploit | Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectmicrofocus · arcsight enterprise security manager | Critical10.0 | — | 3.0% | Mar 13, 2015 |
40Plan | CVE-2021-22504No exploit | Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, microfocus · operations bridge manager | Critical9.8 | — | 3.5% | Feb 12, 2021 |
40Plan | CVE-2018-6498No exploit | Micro Focus Container Deployment Foundation (CDF), Remote Code Executionmicrofocus · data center automation · CWE-94 | Critical9.8 | — | 3.1% | Aug 30, 2018 |
40Plan | CVE-2020-11851Proof of concept | Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1.microfocus · arcsight logger · CWE-94 | Critical9.8 | — | 2.9% | Nov 16, 2020 |
40Plan | CVE-2019-3476No exploit | Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.microfocus · data protector | Critical9.8 | — | 2.9% | Mar 25, 2019 |
40Plan | CVE-2016-9176No exploit | Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or atmicrofocus · rumba · CWE-119 | Critical9.8 | — | 2.8% | Nov 3, 2016 |
40Plan | CVE-2017-7420No exploit | An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer anmicrofocus · enterprise developer · CWE-287 | Critical9.8 | — | 2.4% | Aug 21, 2017 |
40Plan | CVE-2018-6499No exploit | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bmicrofocus · data center automation · CWE-94 | Critical9.8 | — | 2.4% | Aug 30, 2018 |
40Plan | CVE-2018-7679No exploit | Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories microfocus · solutions business manager · CWE-20 | Critical9.8 | — | 2.3% | Jun 21, 2018 |
- CVE-2021-2250298Now
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40.
CriticalCVSS 9.8KEVWeaponizedEPSS 97%microfocus · operation bridge reporterFeb 8, 2021
- CVE-2021-2250668This week
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to versio
HighCVSS 7.5KEVWeaponizedEPSS 26%microfocus · access managerMar 26, 2021
- CVE-2019-573664This week
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
HighCVSS 8.6WeaponizedEPSS 98%docker · dockerFeb 11, 2019
- CVE-2018-1246463This week
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
CriticalCVSS 9.8WeaponizedEPSS 81%microfocus · secure messaging gatewayJun 29, 2018
- CVE-2020-1185461This week
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
CriticalCVSS 9.8WeaponizedEPSS 74%microfocus · application performance managementOct 27, 2020
- CVE-2012-593259Plan
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1
CriticalCVSS 10.0WeaponizedEPSS 63%microfocus · privileged user managerDec 24, 2012
- CVE-2020-1185358Plan
Arbitrary code execution vulnerability on multiple Micro Focus products
HighCVSS 8.8WeaponizedEPSS 77%microfocus · operation bridge managerOct 22, 2020
- CVE-2012-043258Plan
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an u
CriticalCVSS 10.0WeaponizedEPSS 59%microfocus · edirectoryDec 25, 2012
- CVE-2016-160653Plan
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitr
CriticalCVSS 9.8Proof of conceptEPSS 46%microfocus · rumbaJul 2, 2016
- CVE-2018-1246552Plan
Remote Code Execution in Micro Focus Secure Messaging Gateway
HighCVSS 7.2WeaponizedEPSS 80%microfocus · secure messaging gatewayJun 29, 2018
- CVE-2020-1185744Plan
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
CriticalCVSS 9.8WeaponizedEPSS 16%microfocus · operation bridge reporterSep 22, 2020
- CVE-2016-522844Plan
Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11
CriticalCVSS 9.8Proof of conceptEPSS 15%microfocus · rumbaJul 2, 2016
- CVE-2015-694643Plan
Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary
CriticalCVSS 9.3No exploitEPSS 21%microfocus · accurevSep 15, 2015
- CVE-2008-712643Plan
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of se
CriticalCVSS 10.0Proof of conceptEPSS 10%microfocus · visibrokerAug 31, 2009
- CVE-2009-515341Plan
In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allo
CriticalCVSS 9.8No exploitEPSS 6%microfocus · netwareNov 21, 2018
- CVE-2020-1185641Plan
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
CriticalCVSS 9.8No exploitEPSS 5%microfocus · operation bridge reporterSep 22, 2020
- CVE-2014-788541Plan
Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vect
CriticalCVSS 10.0No exploitEPSS 3%microfocus · arcsight enterprise security managerMar 13, 2015
- CVE-2021-2250440Plan
Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11,
CriticalCVSS 9.8No exploitEPSS 3%microfocus · operations bridge managerFeb 12, 2021
- CVE-2018-649840Plan
Micro Focus Container Deployment Foundation (CDF), Remote Code Execution
CriticalCVSS 9.8No exploitEPSS 3%microfocus · data center automationAug 30, 2018
- CVE-2020-1185140Plan
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1.
CriticalCVSS 9.8Proof of conceptEPSS 3%microfocus · arcsight loggerNov 16, 2020
- CVE-2019-347640Plan
Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.
CriticalCVSS 9.8No exploitEPSS 3%microfocus · data protectorMar 25, 2019
- CVE-2016-917640Plan
Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or at
CriticalCVSS 9.8No exploitEPSS 3%microfocus · rumbaNov 3, 2016
- CVE-2017-742040Plan
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer an
CriticalCVSS 9.8No exploitEPSS 2%microfocus · enterprise developerAug 21, 2017
- CVE-2018-649940Plan
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations B
CriticalCVSS 9.8No exploitEPSS 2%microfocus · data center automationAug 30, 2018
- CVE-2018-767940Plan
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories
CriticalCVSS 9.8No exploitEPSS 2%microfocus · solutions business managerJun 21, 2018