microfocus kayıtları
microfocus üreticisine ait 276 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %0,7
- Silahlaştırılmış
- 13 · %4,7
- Pre-auth RCE
- 35
- Düzeltme kaydı olan
- %12
- Yayından KEV’e ortanca
- 245 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')56
- CWE-611 Improper Restriction of XML External Entity Reference13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-20 Improper Input Validation8
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
276 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2021-22502Silahlaştırılmış | Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40.microfocus · operation bridge reporter · CWE-78 | Kritik9,8 | KEV | %96,7 | 8 Şub 2021 |
68Bu hafta | CVE-2021-22506Silahlaştırılmış | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to versiomicrofocus · access manager | Yüksek7,5 | KEV | %25,7 | 26 Mar 2021 |
64Bu hafta | CVE-2019-5736Silahlaştırılmış | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequendocker · docker · CWE-78 | Yüksek8,6 | — | %98,5 | 11 Şub 2019 |
63Bu hafta | CVE-2018-12464Silahlaştırılmış | Unauthenticated SQL injection in Micro Focus Secure Messaging Gatewaymicrofocus · secure messaging gateway · CWE-89 | Kritik9,8 | — | %80,7 | 29 Haz 2018 |
61Bu hafta | CVE-2020-11854Silahlaştırılmış | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.microfocus · application performance management · CWE-798 | Kritik9,8 | — | %74,4 | 27 Eki 2020 |
59Planlayın | CVE-2012-5932Silahlaştırılmış | Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1microfocus · privileged user manager · CWE-94 | Kritik10,0 | — | %62,8 | 24 Ara 2012 |
58Planlayın | CVE-2020-11853Silahlaştırılmış | Arbitrary code execution vulnerability on multiple Micro Focus productsmicrofocus · operation bridge manager | Yüksek8,8 | — | %77,0 | 22 Eki 2020 |
58Planlayın | CVE-2012-0432Silahlaştırılmış | Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an umicrofocus · edirectory · CWE-119 | Kritik10,0 | — | %58,7 | 25 Ara 2012 |
53Planlayın | CVE-2016-1606Kavram kanıtı | Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrmicrofocus · rumba · CWE-119 | Kritik9,8 | — | %45,6 | 2 Tem 2016 |
52Planlayın | CVE-2018-12465Silahlaştırılmış | Remote Code Execution in Micro Focus Secure Messaging Gatewaymicrofocus · secure messaging gateway · CWE-77 | Yüksek7,2 | — | %80,0 | 29 Haz 2018 |
44Planlayın | CVE-2020-11857Silahlaştırılmış | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.microfocus · operation bridge reporter · CWE-798 | Kritik9,8 | — | %15,8 | 22 Eyl 2020 |
44Planlayın | CVE-2016-5228Kavram kanıtı | Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11microfocus · rumba · CWE-119 | Kritik9,8 | — | %15,1 | 2 Tem 2016 |
43Planlayın | CVE-2015-6946İstismar yok | Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary microfocus · accurev · CWE-119 | Kritik9,3 | — | %21,2 | 15 Eyl 2015 |
43Planlayın | CVE-2008-7126Kavram kanıtı | Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of semicrofocus · visibroker · CWE-189 | Kritik10,0 | — | %10,0 | 31 Ağu 2009 |
41Planlayın | CVE-2009-5153İstismar yok | In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allomicrofocus · netware · CWE-119 | Kritik9,8 | — | %6,1 | 21 Kas 2018 |
41Planlayın | CVE-2020-11856İstismar yok | Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.microfocus · operation bridge reporter · CWE-306 | Kritik9,8 | — | %5,2 | 22 Eyl 2020 |
41Planlayın | CVE-2014-7885İstismar yok | Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectmicrofocus · arcsight enterprise security manager | Kritik10,0 | — | %3,0 | 13 Mar 2015 |
40Planlayın | CVE-2021-22504İstismar yok | Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, microfocus · operations bridge manager | Kritik9,8 | — | %3,5 | 12 Şub 2021 |
40Planlayın | CVE-2018-6498İstismar yok | Micro Focus Container Deployment Foundation (CDF), Remote Code Executionmicrofocus · data center automation · CWE-94 | Kritik9,8 | — | %3,1 | 30 Ağu 2018 |
40Planlayın | CVE-2020-11851Kavram kanıtı | Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1.microfocus · arcsight logger · CWE-94 | Kritik9,8 | — | %2,9 | 16 Kas 2020 |
40Planlayın | CVE-2019-3476İstismar yok | Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.microfocus · data protector | Kritik9,8 | — | %2,9 | 25 Mar 2019 |
40Planlayın | CVE-2016-9176İstismar yok | Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or atmicrofocus · rumba · CWE-119 | Kritik9,8 | — | %2,8 | 3 Kas 2016 |
40Planlayın | CVE-2017-7420İstismar yok | An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer anmicrofocus · enterprise developer · CWE-287 | Kritik9,8 | — | %2,4 | 21 Ağu 2017 |
40Planlayın | CVE-2018-6499İstismar yok | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bmicrofocus · data center automation · CWE-94 | Kritik9,8 | — | %2,4 | 30 Ağu 2018 |
40Planlayın | CVE-2018-7679İstismar yok | Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories microfocus · solutions business manager · CWE-20 | Kritik9,8 | — | %2,3 | 21 Haz 2018 |
- CVE-2021-2250298Hemen
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97microfocus · operation bridge reporter8 Şub 2021
- CVE-2021-2250668Bu hafta
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to versio
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %26microfocus · access manager26 Mar 2021
- CVE-2019-573664Bu hafta
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequen
YüksekCVSS 8,6SilahlaştırılmışEPSS %98docker · docker11 Şub 2019
- CVE-2018-1246463Bu hafta
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
KritikCVSS 9,8SilahlaştırılmışEPSS %81microfocus · secure messaging gateway29 Haz 2018
- CVE-2020-1185461Bu hafta
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
KritikCVSS 9,8SilahlaştırılmışEPSS %74microfocus · application performance management27 Eki 2020
- CVE-2012-593259Planlayın
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1
KritikCVSS 10,0SilahlaştırılmışEPSS %63microfocus · privileged user manager24 Ara 2012
- CVE-2020-1185358Planlayın
Arbitrary code execution vulnerability on multiple Micro Focus products
YüksekCVSS 8,8SilahlaştırılmışEPSS %77microfocus · operation bridge manager22 Eki 2020
- CVE-2012-043258Planlayın
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an u
KritikCVSS 10,0SilahlaştırılmışEPSS %59microfocus · edirectory25 Ara 2012
- CVE-2016-160653Planlayın
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitr
KritikCVSS 9,8Kavram kanıtıEPSS %46microfocus · rumba2 Tem 2016
- CVE-2018-1246552Planlayın
Remote Code Execution in Micro Focus Secure Messaging Gateway
YüksekCVSS 7,2SilahlaştırılmışEPSS %80microfocus · secure messaging gateway29 Haz 2018
- CVE-2020-1185744Planlayın
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
KritikCVSS 9,8SilahlaştırılmışEPSS %16microfocus · operation bridge reporter22 Eyl 2020
- CVE-2016-522844Planlayın
Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11
KritikCVSS 9,8Kavram kanıtıEPSS %15microfocus · rumba2 Tem 2016
- CVE-2015-694643Planlayın
Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary
KritikCVSS 9,3İstismar yokEPSS %21microfocus · accurev15 Eyl 2015
- CVE-2008-712643Planlayın
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of se
KritikCVSS 10,0Kavram kanıtıEPSS %10microfocus · visibroker31 Ağu 2009
- CVE-2009-515341Planlayın
In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allo
KritikCVSS 9,8İstismar yokEPSS %6microfocus · netware21 Kas 2018
- CVE-2020-1185641Planlayın
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
KritikCVSS 9,8İstismar yokEPSS %5microfocus · operation bridge reporter22 Eyl 2020
- CVE-2014-788541Planlayın
Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vect
KritikCVSS 10,0İstismar yokEPSS %3microfocus · arcsight enterprise security manager13 Mar 2015
- CVE-2021-2250440Planlayın
Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11,
KritikCVSS 9,8İstismar yokEPSS %3microfocus · operations bridge manager12 Şub 2021
- CVE-2018-649840Planlayın
Micro Focus Container Deployment Foundation (CDF), Remote Code Execution
KritikCVSS 9,8İstismar yokEPSS %3microfocus · data center automation30 Ağu 2018
- CVE-2020-1185140Planlayın
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1.
KritikCVSS 9,8Kavram kanıtıEPSS %3microfocus · arcsight logger16 Kas 2020
- CVE-2019-347640Planlayın
Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.
KritikCVSS 9,8İstismar yokEPSS %3microfocus · data protector25 Mar 2019
- CVE-2016-917640Planlayın
Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or at
KritikCVSS 9,8İstismar yokEPSS %3microfocus · rumba3 Kas 2016
- CVE-2017-742040Planlayın
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer an
KritikCVSS 9,8İstismar yokEPSS %2microfocus · enterprise developer21 Ağu 2017
- CVE-2018-649940Planlayın
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations B
KritikCVSS 9,8İstismar yokEPSS %2microfocus · data center automation30 Ağu 2018
- CVE-2018-767940Planlayın
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories
KritikCVSS 9,8İstismar yokEPSS %2microfocus · solutions business manager21 Haz 2018