Записи microfocus
276 опубликованных записей вендора microfocus.
Профиль для исследователя
- Попали в KEV
- 2 · 0,7 %
- С эксплойтом
- 13 · 4,7 %
- Pre-auth RCE
- 35
- С записью об исправлении
- 12 %
- Медиана: публикация → KEV
- 245 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')56
- CWE-611 Improper Restriction of XML External Entity Reference13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-20 Improper Input Validation8
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
276 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2021-22502Готовый эксплойт | Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40.microfocus · operation bridge reporter · CWE-78 | Критическая9,8 | KEV | 96,7 % | 8 февр. 2021 г. |
68На этой неделе | CVE-2021-22506Готовый эксплойт | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to versiomicrofocus · access manager | Высокая7,5 | KEV | 25,7 % | 26 мар. 2021 г. |
64На этой неделе | CVE-2019-5736Готовый эксплойт | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | Высокая8,6 | — | 98,5 % | 11 февр. 2019 г. |
63На этой неделе | CVE-2018-12464Готовый эксплойт | Unauthenticated SQL injection in Micro Focus Secure Messaging Gatewaymicrofocus · secure messaging gateway · CWE-89 | Критическая9,8 | — | 80,7 % | 29 июн. 2018 г. |
61На этой неделе | CVE-2020-11854Готовый эксплойт | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.microfocus · application performance management · CWE-798 | Критическая9,8 | — | 74,4 % | 27 окт. 2020 г. |
59В плане | CVE-2012-5932Готовый эксплойт | Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1microfocus · privileged user manager · CWE-94 | Критическая10,0 | — | 62,8 % | 24 дек. 2012 г. |
58В плане | CVE-2020-11853Готовый эксплойт | Arbitrary code execution vulnerability on multiple Micro Focus productsmicrofocus · operation bridge manager | Высокая8,8 | — | 77,0 % | 22 окт. 2020 г. |
58В плане | CVE-2012-0432Готовый эксплойт | Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an umicrofocus · edirectory · CWE-119 | Критическая10,0 | — | 58,7 % | 25 дек. 2012 г. |
53В плане | CVE-2016-1606Proof of concept | Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrmicrofocus · rumba · CWE-119 | Критическая9,8 | — | 45,6 % | 2 июл. 2016 г. |
52В плане | CVE-2018-12465Готовый эксплойт | Remote Code Execution in Micro Focus Secure Messaging Gatewaymicrofocus · secure messaging gateway · CWE-77 | Высокая7,2 | — | 80,0 % | 29 июн. 2018 г. |
44В плане | CVE-2020-11857Готовый эксплойт | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.microfocus · operation bridge reporter · CWE-798 | Критическая9,8 | — | 15,8 % | 22 сент. 2020 г. |
44В плане | CVE-2016-5228Proof of concept | Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11microfocus · rumba · CWE-119 | Критическая9,8 | — | 15,1 % | 2 июл. 2016 г. |
43В плане | CVE-2015-6946Эксплойта нет | Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary microfocus · accurev · CWE-119 | Критическая9,3 | — | 21,2 % | 15 сент. 2015 г. |
43В плане | CVE-2008-7126Proof of concept | Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of semicrofocus · visibroker · CWE-189 | Критическая10,0 | — | 10,0 % | 31 авг. 2009 г. |
41В плане | CVE-2009-5153Эксплойта нет | In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allomicrofocus · netware · CWE-119 | Критическая9,8 | — | 6,1 % | 21 нояб. 2018 г. |
41В плане | CVE-2020-11856Эксплойта нет | Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.microfocus · operation bridge reporter · CWE-306 | Критическая9,8 | — | 5,2 % | 22 сент. 2020 г. |
41В плане | CVE-2014-7885Эксплойта нет | Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectmicrofocus · arcsight enterprise security manager | Критическая10,0 | — | 3,0 % | 13 мар. 2015 г. |
40В плане | CVE-2021-22504Эксплойта нет | Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, microfocus · operations bridge manager | Критическая9,8 | — | 3,5 % | 12 февр. 2021 г. |
40В плане | CVE-2018-6498Эксплойта нет | Micro Focus Container Deployment Foundation (CDF), Remote Code Executionmicrofocus · data center automation · CWE-94 | Критическая9,8 | — | 3,1 % | 30 авг. 2018 г. |
40В плане | CVE-2020-11851Proof of concept | Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1.microfocus · arcsight logger · CWE-94 | Критическая9,8 | — | 2,9 % | 16 нояб. 2020 г. |
40В плане | CVE-2019-3476Эксплойта нет | Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.microfocus · data protector | Критическая9,8 | — | 2,9 % | 25 мар. 2019 г. |
40В плане | CVE-2016-9176Эксплойта нет | Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or atmicrofocus · rumba · CWE-119 | Критическая9,8 | — | 2,8 % | 3 нояб. 2016 г. |
40В плане | CVE-2017-7420Эксплойта нет | An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer anmicrofocus · enterprise developer · CWE-287 | Критическая9,8 | — | 2,4 % | 21 авг. 2017 г. |
40В плане | CVE-2018-6499Эксплойта нет | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bmicrofocus · data center automation · CWE-94 | Критическая9,8 | — | 2,4 % | 30 авг. 2018 г. |
40В плане | CVE-2018-7679Эксплойта нет | Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories microfocus · solutions business manager · CWE-20 | Критическая9,8 | — | 2,3 % | 21 июн. 2018 г. |
- CVE-2021-2250298Срочно
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %microfocus · operation bridge reporter8 февр. 2021 г.
- CVE-2021-2250668На этой неделе
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to versio
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 26 %microfocus · access manager26 мар. 2021 г.
- CVE-2019-573664На этой неделе
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
ВысокаяCVSS 8,6Готовый эксплойтEPSS 98 %docker · docker11 февр. 2019 г.
- CVE-2018-1246463На этой неделе
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
КритическаяCVSS 9,8Готовый эксплойтEPSS 81 %microfocus · secure messaging gateway29 июн. 2018 г.
- CVE-2020-1185461На этой неделе
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
КритическаяCVSS 9,8Готовый эксплойтEPSS 74 %microfocus · application performance management27 окт. 2020 г.
- CVE-2012-593259В плане
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1
КритическаяCVSS 10,0Готовый эксплойтEPSS 63 %microfocus · privileged user manager24 дек. 2012 г.
- CVE-2020-1185358В плане
Arbitrary code execution vulnerability on multiple Micro Focus products
ВысокаяCVSS 8,8Готовый эксплойтEPSS 77 %microfocus · operation bridge manager22 окт. 2020 г.
- CVE-2012-043258В плане
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an u
КритическаяCVSS 10,0Готовый эксплойтEPSS 59 %microfocus · edirectory25 дек. 2012 г.
- CVE-2016-160653В плане
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitr
КритическаяCVSS 9,8Proof of conceptEPSS 46 %microfocus · rumba2 июл. 2016 г.
- CVE-2018-1246552В плане
Remote Code Execution in Micro Focus Secure Messaging Gateway
ВысокаяCVSS 7,2Готовый эксплойтEPSS 80 %microfocus · secure messaging gateway29 июн. 2018 г.
- CVE-2020-1185744В плане
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
КритическаяCVSS 9,8Готовый эксплойтEPSS 16 %microfocus · operation bridge reporter22 сент. 2020 г.
- CVE-2016-522844В плане
Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11
КритическаяCVSS 9,8Proof of conceptEPSS 15 %microfocus · rumba2 июл. 2016 г.
- CVE-2015-694643В плане
Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary
КритическаяCVSS 9,3Эксплойта нетEPSS 21 %microfocus · accurev15 сент. 2015 г.
- CVE-2008-712643В плане
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of se
КритическаяCVSS 10,0Proof of conceptEPSS 10 %microfocus · visibroker31 авг. 2009 г.
- CVE-2009-515341В плане
In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allo
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %microfocus · netware21 нояб. 2018 г.
- CVE-2020-1185641В плане
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %microfocus · operation bridge reporter22 сент. 2020 г.
- CVE-2014-788541В плане
Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vect
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %microfocus · arcsight enterprise security manager13 мар. 2015 г.
- CVE-2021-2250440В плане
Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11,
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %microfocus · operations bridge manager12 февр. 2021 г.
- CVE-2018-649840В плане
Micro Focus Container Deployment Foundation (CDF), Remote Code Execution
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %microfocus · data center automation30 авг. 2018 г.
- CVE-2020-1185140В плане
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %microfocus · arcsight logger16 нояб. 2020 г.
- CVE-2019-347640В плане
Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %microfocus · data protector25 мар. 2019 г.
- CVE-2016-917640В плане
Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or at
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %microfocus · rumba3 нояб. 2016 г.
- CVE-2017-742040В плане
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer an
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microfocus · enterprise developer21 авг. 2017 г.
- CVE-2018-649940В плане
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations B
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microfocus · data center automation30 авг. 2018 г.
- CVE-2018-767940В плане
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microfocus · solutions business manager21 июн. 2018 г.