Micro Focus Vulnerabilities and Affected Products
Vulnerabilities associated with Micro Focus Enterprise Developer, Micro Focus Enterprise Server.
Products
Clear product- Service Manager8 vulnerabilities
- Micro Focus Enterprise Developer, Micro Focus Enterprise Server7 vulnerabilities
- NetIQ Access Manager7 vulnerabilities
- Solutions Business Manager7 vulnerabilities
- ArcSight Management Center6 vulnerabilities
- Solutions Business Manager 11.45 vulnerabilities
- ArcSight Logger4 vulnerabilities
- Solutions Business Manager (SBM)4 vulnerabilities
- Dimensions CM3 vulnerabilities
- Filr3 vulnerabilities
- HP ArcSight ESM3 vulnerabilities
- HP ArcSight ESM Express3 vulnerabilities
- Operation Bridge Manager3 vulnerabilities
- Application Performance Management2 vulnerabilities
- Content Manager2 vulnerabilities
- Data Center Automation Containerized Suite2 vulnerabilities
- Fortify Software Security Center (SSC)2 vulnerabilities
- Hybrid Cloud Management2 vulnerabilities
- Hybrid Cloud Management Containerized Suite2 vulnerabilities
- Micro Focus ArcSight Logger2 vulnerabilities
- Micro Focus NetIQ Self Service Password Reset.2 vulnerabilities
- Micro Focus VisiBroker2 vulnerabilities
- NetIQ eDirectory 9.1 SP22 vulnerabilities
- Network Automation2 vulnerabilities
- Network Operations Management (NOM) Suite CDF2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-12469HIGH | Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination. CWE-476Oct 12, 2018 | CVSS7.5v3.0 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-5187HIGH | A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter (CWE-275) configuration information and inject OS commands (CWE-78) via forged requests. | CVSS8.8v3.0 | EPSS0.751% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-7423HIGH | A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is configured. This includes creating new privileged credentials, resulting in privilege elevation (CWE-275). Note esfadmingui is not enabled by default. CWE-352Aug 21, 2017 | CVSS8.8v3.0 | EPSS0.751% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-7420CRITICAL | An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration information and alter the state of the running product (CWE-275). CWE-287Aug 21, 2017 | CVSS9.8v3.0 | EPSS2.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-7421MEDIUM | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features. CWE-79Aug 21, 2017 | CVSS6.1v3.0 | EPSS1.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-7424MEDIUM | A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to download arbitrary files from a system running the product, if this component is configured. Note esfadmingui is not enabled by default. | CVSS6.5v3.0 | EPSS1.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-7422MEDIUM | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features, if this component is configured. Note esfadmingui is not enabled by default. CWE-79Aug 21, 2017 | CVSS5.4v3.0 | EPSS0.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |