Microfocus
Microfocus Imanager: vulnerabilidades y CVE
Microfocus Imanager tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-24467 | Crítica (9.8) | 1.1% | — | 22 nov 2024 | Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000. |
| CVE-2023-24466 | Crítica (9.8) | 0.53% | — | 22 nov 2024 | Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200. |
| CVE-2022-26324 | Media (5.4) | 0.29% | — | 22 nov 2024 | Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000. |
| CVE-2021-38135 | Crítica (9.8) | 0.45% | — | 22 nov 2024 | Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000. |
| CVE-2021-38134 | Media (6.1) | 0.29% | — | 22 nov 2024 | Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000. |
| CVE-2021-38119 | Media (6.1) | 0.31% | — | 22 nov 2024 | Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. |
| CVE-2021-38118 | Alta (7.8) | 0.21% | — | 22 nov 2024 | Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. |
| CVE-2021-38117 | Crítica (9.8) | 1.1% | — | 22 nov 2024 | Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. |
| CVE-2021-38116 | Alta (8.8) | 0.62% | — | 22 nov 2024 | Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5 |
| CVE-2020-11859 | Media (5.4) | 0.33% | — | 6 nov 2024 | Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3 |
| CVE-2024-4429 | Alta (7.4) | 0.18% | — | 28 may 2024 | Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure. |
| CVE-2024-3969 | Crítica (9.8) | 0.50% | — | 28 may 2024 | XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload |
| CVE-2024-3970 | Alta (7.5) | 0.51% | — | 15 may 2024 | Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal. |
| CVE-2024-3968 | Crítica (9.8) | 0.68% | — | 15 may 2024 | Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task. |
| CVE-2024-3967 | Crítica (9.8) | 0.64% | — | 15 may 2024 | Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization. |
| CVE-2024-3488 | Crítica (9.8) | 0.37% | — | 15 may 2024 | File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication. |
| CVE-2024-3487 | Crítica (9.8) | 0.42% | — | 15 may 2024 | Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication. |
| CVE-2024-3486 | Crítica (9.8) | 0.47% | — | 15 may 2024 | XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution. |
| CVE-2024-3485 | Alta (7.5) | 0.26% | — | 15 may 2024 | Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure. |
| CVE-2024-3484 | Crítica (9.8) | 0.51% | — | 15 may 2024 | Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure. |
| CVE-2024-3483 | Crítica (9.8) | 0.98% | — | 15 may 2024 | Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues. |
| CVE-2018-17949 | Media (6.1) | 0.65% | — | 12 dic 2018 | Cross site scripting vulnerability in iManager prior to 3.1 SP2. |
Otros productos de Microfocus
Access Manager · 18Solutions Business Manager · 17Edirectory · 16Service Manager · 16Enterprise Server · 12Enterprise Developer · 12Netiq Advanced Authentication · 11Application Automation Tools · 9Arcsight Logger · 9Arcsight Enterprise Security Manager · 8Arcsight Management Center · 8Operations Agent · 7