Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
362 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.9% | — | Microfocus Data Protector | 25/3/2019 | 17/6/2026 | Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution. | |
| Modificada | Alta (7.5) | 0.88% | — | Microfocus Netiq Edirectory | 21/3/2019 | 17/6/2026 | NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security. | |
| Modificada | Alta (7.8) | 0.99% | 💥 Exploit | Microfocus Filr | 20/2/2019 | 17/6/2026 | A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. This vulnerability affects all versions of Filr 3.x prior to Security Update 6. | |
| Modificada | Media (6.5) | 9.0% | 💥 Exploit | Microfocus Filr | 20/2/2019 | 17/6/2026 | A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6. | |
| Modificada | Crítica (9.8) | 1.4% | — | Microfocus Solutions Business Manager | 12/2/2019 | 17/6/2026 | An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. | |
| Modificada | Alta (8.6) | 98% | 💥 Exploit | DockerLinuxfoundation RuncRedhat Container Development KITRedhat Openshift+15 | 11/2/2019 | 17/6/2026 | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image,… | |
| Modificada | Media (6.5) | 7.2% | 💥 Exploit | Microfocus Fortify Software Security Center | 13/12/2018 | 17/6/2026 | A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access | |
| Modificada | Media (6.5) | 7.4% | 💥 Exploit | Microfocus Fortify Software Security Center | 13/12/2018 | 17/6/2026 | A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Edirectory | 12/12/2018 | 17/6/2026 | Cross site scripting vulnerability in eDirectory prior to 9.1 SP2 | |
| Modificada | Alta (7.5) | 0.83% | — | Microfocus Edirectory | 12/12/2018 | 17/6/2026 | Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Imanager | 12/12/2018 | 17/6/2026 | Cross site scripting vulnerability in iManager prior to 3.1 SP2. | |
| Modificada | Crítica (9.8) | 6.1% | — | Microfocus Netware | 21/11/2018 | 16/6/2026 | In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote unauthenticated attackers to execute code, because a length field was incorrectly trusted. | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Access Manager | 20/11/2018 | 17/6/2026 | An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3. | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Access Manager | 15/11/2018 | 17/6/2026 | Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3. | |
| Modificada | Media (6.5) | 1.0% | — | Microfocus Service Manager | 13/11/2018 | 17/6/2026 | A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51. The vulnerability could be exploited to release unauthorized disclosure of data. | |
| Modificada | Alta (8.8) | 1.0% | — | Microfocus Operations Bridge | 7/11/2018 | 17/6/2026 | A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge containerized suite versions 2017.11, 2018.02, 2018.05, 2018.08. This vulnerability could allow for information disclosure. | |
| Modificada | Alta (8.8) | 1.7% | — | Microfocus Real User Monitoring | 23/10/2018 | 17/6/2026 | A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise Server | 12/10/2018 | 17/6/2026 | Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference… | |
| Modificada | Alta (8.8) | 0.57% | — | Microfocus Arcsight Management Center | 20/9/2018 | 17/6/2026 | A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81. This vulnerability could be exploited to allow for Cross-Site Request Forgery (CSRF). | |
| Modificada | Alta (8.8) | 3.8% | — | Informationbuilders Webfocus | 7/9/2018 | 17/6/2026 | An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 . A specially crafted web parameter can cause a command injection. An authenticated attacker can send a crafted web request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.4% | — | Microfocus Data Center AutomationMicrofocus Hybrid Cloud ManagementMicrofocus Network Operations ManagementMicrofocus Operations Bridge+4 | 30/8/2018 | 17/6/2026 | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02,… | |
| Modificada | Crítica (9.8) | 3.1% | — | Microfocus Data Center AutomationMicrofocus Hybrid Cloud ManagementMicrofocus Network Operations ManagementMicrofocus Operations Bridge+1 | 30/8/2018 | 17/6/2026 | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02,… | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Edirectory | 9/8/2018 | 17/6/2026 | Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1. | |
| Modificada | Alta (7.5) | 1.4% | — | Microfocus Edirectory | 9/8/2018 | 17/6/2026 | Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage. | |
| Modificada | Alta (7.2) | 2.2% | — | Microfocus Groupwise | 1/8/2018 | 17/6/2026 | A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server. In certain circumstances this could result in remote code execution. |