Vulnerabilities (CVE)

Filtered by vendor Microfocus Subscribe
Total 273 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-3488 1 Microfocus 1 Imanager 2026-06-17 N/A 5.6 MEDIUM
File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.
CVE-2024-3487 1 Microfocus 1 Imanager 2026-06-17 N/A 3.5 LOW
Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.
CVE-2024-3486 1 Microfocus 1 Imanager 2026-06-17 N/A 7.8 HIGH
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.
CVE-2024-3485 1 Microfocus 1 Imanager 2026-06-17 N/A 5.3 MEDIUM
Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.
CVE-2024-3484 1 Microfocus 1 Imanager 2026-06-17 N/A 5.7 MEDIUM
Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.
CVE-2024-3483 1 Microfocus 1 Imanager 2026-06-17 N/A 7.8 HIGH
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.
CVE-2024-0622 1 Microfocus 1 Operations Agent 2026-06-17 N/A 8.8 HIGH
Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platforms. The vulnerability could allow local privilege escalation. 
CVE-2023-5913 1 Microfocus 1 Fortify Scancentral Dast 2026-06-17 N/A 8.2 HIGH
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1.
CVE-2023-4964 1 Microfocus 2 Asset Management X, Service Management Automation X 2026-06-17 N/A 8.2 HIGH
Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset Management X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11. The vulnerability could allow attackers to redirect a user to malicious websites.
CVE-2023-32268 1 Microfocus 1 Filr 2026-06-17 N/A 7.2 HIGH
Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.
CVE-2023-32267 1 Microfocus 1 Arcsight Management Center 2026-06-17 N/A 6.4 MEDIUM
A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited.
CVE-2023-32265 1 Microfocus 5 Cobol Server, Enterprise Developer, Enterprise Server and 2 more 2026-06-17 N/A 7.1 HIGH
A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this vulnerability. As described in the hardening guide in the product documentation, other mitigations including restricting network access to ESCWA and restricting users’ permissions in the Micro Focus Directory Server also reduce the exposure to this issue. Given the right conditions this vulnerability could be exploited to expose a service account password. The account corresponding to the exposed credentials usually has limited privileges and, in many cases would only be useful for extracting details of other user accounts and similar information.
CVE-2023-32263 1 Microfocus 1 Dimensions Cm 2026-06-17 N/A 2.6 LOW
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability only applies when the Jenkins plugin is configured to use login certificate credentials. https://www.jenkins.io/security/advisory/2023-06-14/
CVE-2023-32262 1 Microfocus 1 Dimensions Cm 2026-06-17 N/A 4.3 MEDIUM
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Item/Configure permission to access and capture credentials they are not entitled to. See the following Jenkins security advisory for details: * https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/
CVE-2023-32261 1 Microfocus 1 Dimensions Cm 2026-06-17 N/A 4.2 MEDIUM
A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. See the following Jenkins security advisory for details: * https://www.jenkins.io/security/advisory/2023-06-14/ https://www.jenkins.io/security/advisory/2023-06-14/
CVE-2023-24470 1 Microfocus 1 Arcsight Logger 2026-06-17 N/A 9.1 CRITICAL
Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.
CVE-2023-24469 1 Microfocus 1 Arcsight Logger 2026-06-17 N/A 6.1 MEDIUM
Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0
CVE-2023-24468 1 Microfocus 1 Netiq Advanced Authentication 2026-06-17 N/A 9.8 CRITICAL
Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2
CVE-2023-24467 1 Microfocus 1 Imanager 2026-06-17 N/A 8.8 HIGH
Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.
CVE-2023-24466 1 Microfocus 1 Imanager 2026-06-17 N/A 7.5 HIGH
Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.