Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
362 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.48% | — | Microfocus Application Performance Management | 6/2/2021 | 17/6/2026 | Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing. | |
| Modificada | Media (4.8) | 0.61% | — | Microfocus Application Performance Management | 6/2/2021 | 17/6/2026 | Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow persistent XSS attack. | |
| Modificada | Alta (8.1) | 0.96% | — | Microfocus Application Lifecycle Management | 19/1/2021 | 17/6/2026 | XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited to allow an XML External Entity… | |
| Modificada | Media (6.5) | 0.85% | — | Microfocus Filr | 11/12/2020 | 17/6/2026 | Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x versions. The vulnerability could be exploited to disclose unauthorized sensitive information. | |
| Modificada | Crítica (9.8) | 1.2% | — | Microfocus Identity Manager | 20/11/2020 | 17/6/2026 | NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1. | |
| Modificada | Media (4.8) | 0.52% | — | Microfocus Idol | 17/11/2020 | 17/6/2026 | Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. The vulnerability could be exploited to perform Persistent XSS attack. | |
| Modificada | Media (5.4) | 0.51% | — | Microfocus Filr | 17/11/2020 | 17/6/2026 | Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability could be exploited to perform Reflected XSS attack. | |
| Modificada | Crítica (9.8) | 2.9% | 💥 PoC | Microfocus Arcsight Logger | 17/11/2020 | 17/6/2026 | Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code. | |
| Modificada | Media (5.4) | 0.69% | — | Microfocus Arcsight Logger | 17/11/2020 | 17/6/2026 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS). | |
| Modificada | Media (6.1) | 0.64% | — | Microfocus Arcsight Logger | 17/11/2020 | 17/6/2026 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS) | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Self Service Password Reset | 5/11/2020 | 17/6/2026 | Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information. | |
| Modificada | Alta (7.8) | 2.7% | 💥 Exploit | Microfocus Operations BridgeMicrofocus Operations Bridge Manager | 27/10/2020 | 17/6/2026 | Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Bridge (containerized). The vulneravility affects: 1.) Operation Bridge Manager versions: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier… | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | Microfocus Application Performance ManagementMicrofocus Operations BridgeMicrofocus Operations Bridge Manager | 27/10/2020 | 17/6/2026 | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.)… | |
| Modificada | Alta (8.8) | 77% | 💥 Exploit | Microfocus Operation Bridge ManagerMicrofocus Operations Bridge ManagerHP Universal Cmbd FoundationMicrofocus Application Performance Management+3 | 22/10/2020 | 17/6/2026 | Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP… | |
| Modificada | Media (5.9) | 2.7% | — | SAP Focused RUNSAP Solution Manager | 20/10/2020 | 17/6/2026 | SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator.This may impact the confidentiality of the service. | |
| Modificada | Crítica (9.8) | 5.2% | — | Microfocus Operation Bridge Reporter | 22/9/2020 | 17/6/2026 | Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Microfocus Operation Bridge Reporter | 22/9/2020 | 17/6/2026 | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user | |
| Modificada | Alta (7.8) | 1.3% | 💥 Exploit | Microfocus Operation Bridge Reporter | 22/9/2020 | 17/6/2026 | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with escalated privileges. | |
| Modificada | Alta (7.8) | 0.35% | — | Microfocus Operations Agent | 18/9/2020 | 17/6/2026 | Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11. The vulnerability could be exploited to escalate the local privileges and gain root access on the system. | |
| Modificada | Alta (7.5) | 1.0% | — | Microfocus Arcsight Management Center | 19/8/2020 | 17/6/2026 | Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions prior to version 2.9.5. The vulnerability could cause the server to become unavailable, causing a denial of service. | |
| Modificada | Alta (8.8) | 1.4% | — | Microfocus Secure Messaging Gateway | 7/8/2020 | 17/6/2026 | DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key information to inject system commands into the call to the DKIM system command. | |
| Modificada | Crítica (9.8) | 1.2% | — | Microfocus Identity Manager | 8/7/2020 | 17/6/2026 | Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an unauthorized access. | |
| Modificada | Alta (8.2) | 1.9% | — | IBI Webfocus Business Intelligence | 22/6/2020 | 17/6/2026 | In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local files or forge server-side HTTP requests via a crafted HTTP request to /ibi_apps/WFServlet.cfg because XML external entity injection is possible. This is related to making changes to the application… | |
| Modificada | Alta (8.8) | 0.48% | — | IBI Webfocus Business Intelligence | 22/6/2020 | 17/6/2026 | WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user. It can also be exploited in conjunction with CVE-2016-9044. | |
| Modificada | Media (6.1) | 0.67% | — | IBI Webfocus Business Intelligence | 22/6/2020 | 17/6/2026 | WebFOCUS Business Intelligence 8.0 (SP6) was prone to XSS via arbitrary URL parameters. |