Show filters
263 Total Results
Displaying 201-210 of 263
Sort by:
Attacker Value
Unknown

CVE-2018-7680

Disclosure Date: June 21, 2018 (last updated November 08, 2023)
Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.
0
Attacker Value
Unknown

CVE-2018-7679

Disclosure Date: June 21, 2018 (last updated November 08, 2023)
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.
0
Attacker Value
Unknown

MFSBGN03809 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF

Disclosure Date: June 16, 2018 (last updated November 08, 2023)
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
Attacker Value
Unknown

MFSBGN03810 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF

Disclosure Date: June 16, 2018 (last updated November 08, 2023)
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
Attacker Value
Unknown

MFSBGN03808 rev.1 - Micro Focus UCMDB, Cross-Site Scripting

Disclosure Date: May 23, 2018 (last updated November 08, 2023)
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).
Attacker Value
Unknown

MFSBGN03807 rev.1 - HP Service Manager Software, Multiple Vulnerabilities

Disclosure Date: May 22, 2018 (last updated November 08, 2023)
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
Attacker Value
Unknown

Client for OES Elevation of Privilege via Buffer Overflow

Disclosure Date: May 21, 2018 (last updated November 08, 2023)
The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevate privileges via a buffer overflow in ncfsd.sys.
0
Attacker Value
Unknown

MFSBGN03803 rev.1 - UCMDB, Installation File Access Control Privilege Escalatio…

Disclosure Date: April 24, 2018 (last updated November 08, 2023)
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.
0
Attacker Value
Unknown

Potential Information Disclosure in Sentinel

Disclosure Date: March 07, 2018 (last updated November 08, 2023)
In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes the interface to timeout so that it requires the user to re-authenticate. If another user is passing by and decides to login, their credentials are accepted. While The user does not inherit any of the other users privileges, they are able to view the previous screen. In this case it is possible that the user can see another users events or configuration information for whatever view is currently showing.
0
Attacker Value
Unknown

Fix for NetIQ shell code upload

Disclosure Date: March 02, 2018 (last updated November 08, 2023)
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
0