Microfocus
Microfocus Edirectory: vulnerabilidades y CVE
Microfocus Edirectory tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-38133 | Media (6.5) | 0.35% | — | 12 sept 2024 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. |
| CVE-2021-38132 | Crítica (9.8) | 0.40% | — | 12 sept 2024 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. |
| CVE-2021-38131 | Media (6.1) | 0.24% | — | 12 sept 2024 | Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000. |
| CVE-2021-22533 | Crítica (9.1) | 0.44% | — | 12 sept 2024 | Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000. |
| CVE-2021-22532 | Alta (7.5) | 0.37% | — | 12 sept 2024 | Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000. |
| CVE-2021-22503 | Media (6.1) | 0.24% | — | 12 sept 2024 | Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000. |
| CVE-2018-17952 | Media (6.1) | 0.65% | — | 12 dic 2018 | Cross site scripting vulnerability in eDirectory prior to 9.1 SP2 |
| CVE-2018-17950 | Alta (7.5) | 0.83% | — | 12 dic 2018 | Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 |
| CVE-2018-7692 | Media (6.1) | 0.65% | — | 9 ago 2018 | Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1. |
| CVE-2018-7686 | Alta (7.5) | 1.4% | — | 9 ago 2018 | Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage. |
| CVE-2017-9285 | Crítica (9.8) | 1.2% | — | 2 mar 2018 | NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services. |
| CVE-2017-7429 | Alta (8.8) | 0.84% | — | 2 mar 2018 | The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server. |
| CVE-2012-0432 | Alta (10) | 59% | — | 25 dic 2012 | Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors. |
| CVE-2012-0430 | Media (6.4) | 2.2% | — | 25 dic 2012 | Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors. |
| CVE-2012-0429 | Media (4) | 1.9% | — | 25 dic 2012 | dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request. |
| CVE-2012-0428 | Media (4.3) | 1.8% | — | 25 dic 2012 | Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Otros productos de Microfocus
Imanager · 22Access Manager · 18Solutions Business Manager · 17Service Manager · 16Enterprise Developer · 12Enterprise Server · 12Netiq Advanced Authentication · 11Application Automation Tools · 9Arcsight Logger · 9Arcsight Enterprise Security Manager · 8Arcsight Management Center · 8Operations Agent · 7