CVE-2019-11661

HIGH

Micro Focus Service Manager <9.63 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. This vulnerability could be exploited to allow unauthorized access and modification of data.

References (1)

Core 1
Core References
Various Sources x_refsource_confirm
https://softwaresupport.softwaregrp.com/doc/KM03518316

Scores

CVSS v3 8.3
EPSS 0.0042
EPSS Percentile 62.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Details

Status published
Products (1)
microfocus/service_manager 9.30 - 9.62
Published Sep 18, 2019
Tracked Since Feb 18, 2026