Where
-Infinity
0

Vendor Risk Score

See how microfocus compares to other vendors in security performance

View Risk Score →

Software

microfocus solutions business manager
10
microfocus application automation tools
9
microfocus access manager
5
microfocus application performance management
5
microfocus service manager
5
microfocus edirectory
4
microfocus sentinel
4
microfocus arcsight logger
3
microfocus content manager
3
microfocus operation bridge reporter
3
microfocus operations bridge manager
3
microfocus arcsight management center
2
microfocus cms server
2
microfocus enterprise developer
2
microfocus enterprise server
2
microfocus fortify software security center
2
microfocus netiq advanced authentication
2
microfocus netiq self service password reset
2
microfocus network automation
2
microfocus operations bridge
2
microfocus privileged user manager
2
microfocus service manager automation
2
microfocus ucmdb configuration manager
2
microfocus universal cmdb
2
microfocus arcsight enterprise security manager
1
microfocus autopass license server
1
microfocus bi-directional driver
1
microfocus client open enterprise server
1
microfocus cobol
1
microfocus cobol server
1
microfocus data center automation
1
microfocus enterprise test server
1
microfocus fortify audit workbench
1
microfocus groupwise
1
microfocus hybrid cloud management
1
microfocus identity manager
1
microfocus imanager
1
microfocus operation bridge manager
1
microfocus operations agent
1
microfocus project and portfolio management
1
microfocus project and portfolio management center
1
microfocus real user monitoring
1
microfocus reflection for the web
1
microfocus reflection security gateway
1
microfocus sentinel agent manager
1
microfocus service management automation
1
microfocus service virtualization
1
microfocus universal cmbd browser
1
microfocus universal cmbd server
1
microfocus universal cmdb browser
1
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.

First published (updated )
Severity
10
Code Injection
AV:N/AC:L/Au:N/C:C/I:C/A:C

Eval injection vulnerability in the ldapagnteval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute arbitrary Perl code via a crafted application/x-amf request.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors.

First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.

1 / 2
First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

1 / 2

Remedy

For Operation Bridge Manager https://softwaresupport.softwaregrp.com/doc/KM03747658 For Operation Bridge (containerized) https://softwaresupport.softwaregrp.com/doc/KM03747854 For Application Performance Management https://softwaresupport.softwaregrp.com/doc/KM03747657
First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could allow remote attackers to execute arbitrary code on an OBM server.

First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions 2018.05 to 2019.11. - ArcSight Investigate. versions 2.4.0, 3.0.0 and 3.1.0. - ArcSight Transformation Hub. versions 3.0.0, 3.1.0, 3.2.0. - ArcSight Interset. version 6.0.0. - ArcSight ESM (when ArcSight Fusion 1.0 is installed). version 7.2.1. - Service Management Automation (SMA). versions 2018.05 to 2020.02 - Operation Bridge Suite (Containerized). Versions 2018.05 to 2020.02. - Network Operation Management. versions 2017.11 to 2019.11. - Data Center Automation Containerized. versions 2018.05 to 2019.11 - Identity Intelligence. versions 1.1.0 and 1.1.1. The vulnerability could be exploited to provide unauthorized access to the Container Deployment Foundation.

Remedy

For Data Center Automation Containerized https://softwaresupport.softwaregrp.com/doc/KM03645628 For Network Operation Management https://softwaresupport.softwaregrp.com/doc/KM03645629 For Operation Bridge Suite https://softwaresupport.softwaregrp.com/doc/KM03645630 For SMA https://softwaresupport.softwaregrp.com/doc/KM03645631 For ArcSight apps https://softwaresupport.softwaregrp.com/doc/KM03645642 For Hybrid Cloud Management https://softwaresupport.softwaregrp.com/doc/KM03645636 For Identity Intelligence https://support.microfocus.com/kb/doc.php?id=7024637" } ] }
First published (updated )
Severity
10
Buffer Overflow, Integer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a large string length value to UDP port 14000, which triggers a heap-based buffer overflow.

First published (updated )
Severity
10
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName property value to ObjectXSNAConfig.ObjectXSNAConfig in iconfig.dll, (2) the CPName property value to ObjectXSNAConfig.ObjectXSNAConfig in iconfig.dll, (3) the PrinterName property value to ProfileEditor.PrintPasteControl in ProfEdit.dll, (4) the Data argument to the WriteRecords function in FTXBIFFLib.AS400FtxBIFF in FtxBIFF.dll, (5) the Serialized property value to NMSECCOMPARAMSLib.SSL3 in NMSecComParams.dll, (6) the UserName property value to NMSECCOMPARAMSLib.FirewallProxy in NMSecComParams.dll, (7) the LUName property value to ProfileEditor.MFSNAControl in ProfEdit.dll, (8) the newVal argument to the Load function in FTPSFTPLib.SFtpSession in FTPSFtp.dll, or (9) a long Host field in the FTP Client.

First published (updated )
Severity
10
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF 11997 and 9.4.x before 9.4 HF 12815 allows remote attackers to execute arbitrary code via a long MacroName argument. NOTE: some references mention CVE-2016-5226 but that is not a correct ID for any Rumba vulnerability.

First published (updated )
Severity
10
SQL Injection
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with CVE-2018-12465 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that use the GWAVA product name (i.e. GWAVA 6.5).

Remedy

Please upgrade to Secure Messaging Gateway 471 or newer using the online update tool in the Secure Messaging Gateway management console.
First published (updated )
Severity
9.9
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1

First published (updated )
Severity
9.8
EPSS
0.04%
Input Validation
AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.

First published (updated )
Severity
9.8
EPSS
0.04%
AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.

First published (updated )
Severity
9.8
EPSS
0.04%
Path Traversal
AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.

First published (updated )
Severity
9.8
EPSS
0.04%
Malicious File Upload, Command Injection
AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

First published (updated )
Severity
9.8
EPSS
0.04%
XEE
AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.

First published (updated )
Severity
9.8
EPSS
0.04%
Input Validation, Malicious File Upload
AV:A/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H

File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

First published (updated )
Severity
9.8
EPSS
0.04%
AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.

First published (updated )
Severity
9.8
EPSS
0.04%
XEE
AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload

First published (updated )
Severity
9.8
SSRF
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Possible External Service Interaction attack

in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

First published (updated )
Severity
9.8
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:L/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:L/U:Green

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X.

Remedy

https://portal.microfocus.com/s/article/KM000033373?language=en_US
First published (updated )
Severity
9.8
SSRF
AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Possible External Service Interaction attack

in iManager has been discovered in OpenText™ iManager 3.2.6.0000.

First published (updated )
Severity
9.8
Command Injection, OS Command Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Possible Command Injection

in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.

First published (updated )
Severity
9.8
XEE
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Possible XML External Entity Injection

in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication is used with certain configurations. When the vulnerability is active, authentication succeeds with any valid username, regardless of whether the password is correct; it may also succeed with an invalid username (and any password). This allows an attacker with access to the product to impersonate any user.

Mitigations: The issue is corrected in the upcoming patch update for each affected product. Product overlays and workaround instructions are available through OpenText Support. The vulnerable configurations are believed to be uncommon.

Administrators can test for the vulnerability in their installations by attempting to sign on to a Visual COBOL or Enterprise Server component such as ESCWA using a valid username and incorrect password.

First published (updated )
Severity
9.8
Code Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user

1 / 2
First published (updated )
Severity
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.

First published (updated )
Severity
9.8
Integer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corruption in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203