CVE-2019-11651: XSS

Published Oct 2, 2019
·
Updated

Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. The vulnerability could be exploited to redirect a user to a malicious page or forge certain types of web requests.

Affected Software

68 affected components
Microfocus Enterprise Developer=3.0
Microfocus Enterprise Developer=3.0-patch_1
Microfocus Enterprise Developer=3.0-patch_10
Microfocus Enterprise Developer=3.0-patch_11
Microfocus Enterprise Developer=3.0-patch_12
Microfocus Enterprise Developer=3.0-patch_13
Microfocus Enterprise Developer=3.0-patch_14
Microfocus Enterprise Developer=3.0-patch_15
Microfocus Enterprise Developer=3.0-patch_16
Microfocus Enterprise Developer=3.0-patch_17
Microfocus Enterprise Developer=3.0-patch_18
Microfocus Enterprise Developer=3.0-patch_19
Microfocus Enterprise Developer=3.0-patch_2
Microfocus Enterprise Developer=3.0-patch_3
Microfocus Enterprise Developer=3.0-patch_4
Microfocus Enterprise Developer=3.0-patch_5
Microfocus Enterprise Developer=3.0-patch_6
Microfocus Enterprise Developer=3.0-patch_7
Microfocus Enterprise Developer=3.0-patch_8
Microfocus Enterprise Developer=3.0-patch_9
Microfocus Enterprise Developer=4.0
Microfocus Enterprise Developer=4.0-patch_1
Microfocus Enterprise Developer=4.0-patch_10
Microfocus Enterprise Developer=4.0-patch_11
Microfocus Enterprise Developer=4.0-patch_2
Microfocus Enterprise Developer=4.0-patch_3
Microfocus Enterprise Developer=4.0-patch_4
Microfocus Enterprise Developer=4.0-patch_5
Microfocus Enterprise Developer=4.0-patch_6
Microfocus Enterprise Developer=4.0-patch_7
Microfocus Enterprise Developer=4.0-patch_8
Microfocus Enterprise Developer=4.0-patch_9
Microfocus Enterprise Developer=5.0
Microfocus Enterprise Developer=5.0-patch_1
Microfocus Enterprise Server=3.0
Microfocus Enterprise Server=3.0-patch_1
Microfocus Enterprise Server=3.0-patch_10
Microfocus Enterprise Server=3.0-patch_11
Microfocus Enterprise Server=3.0-patch_12
Microfocus Enterprise Server=3.0-patch_13
Microfocus Enterprise Server=3.0-patch_14
Microfocus Enterprise Server=3.0-patch_15
Microfocus Enterprise Server=3.0-patch_16
Microfocus Enterprise Server=3.0-patch_17
Microfocus Enterprise Server=3.0-patch_18
Microfocus Enterprise Server=3.0-patch_19
Microfocus Enterprise Server=3.0-patch_2
Microfocus Enterprise Server=3.0-patch_3
Microfocus Enterprise Server=3.0-patch_4
Microfocus Enterprise Server=3.0-patch_5
Microfocus Enterprise Server=3.0-patch_6
Microfocus Enterprise Server=3.0-patch_7
Microfocus Enterprise Server=3.0-patch_8
Microfocus Enterprise Server=3.0-patch_9
Microfocus Enterprise Server=4.0
Microfocus Enterprise Server=4.0-patch_1
Microfocus Enterprise Server=4.0-patch_10
Microfocus Enterprise Server=4.0-patch_11
Microfocus Enterprise Server=4.0-patch_2
Microfocus Enterprise Server=4.0-patch_3
Microfocus Enterprise Server=4.0-patch_4
Microfocus Enterprise Server=4.0-patch_5
Microfocus Enterprise Server=4.0-patch_6
Microfocus Enterprise Server=4.0-patch_7
Microfocus Enterprise Server=4.0-patch_8
Microfocus Enterprise Server=4.0-patch_9
Microfocus Enterprise Server=5.0
Microfocus Enterprise Server=5.0-patch_1

Event History

Oct 2, 2019
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-11651?

CVE-2019-11651 is classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS) exploits.

2

How do I fix CVE-2019-11651?

To mitigate CVE-2019-11651, upgrade to Micro Focus Enterprise Developer and Enterprise Server versions 3.0 Patch Update 20, 4.0 Patch Update 12, or 5.0 Patch Update 2 or later.

3

Which versions are affected by CVE-2019-11651?

CVE-2019-11651 affects all versions of Micro Focus Enterprise Developer and Enterprise Server prior to the specified patch updates.

4

What is the nature of the vulnerability described in CVE-2019-11651?

CVE-2019-11651 is a reflected cross-site scripting vulnerability that could enable attackers to redirect users to malicious sites.

5

What can be impacted by exploiting CVE-2019-11651?

Exploiting CVE-2019-11651 could allow attackers to forge web requests or perform unauthorized actions in the context of a user's session.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203