Microfocus
Microfocus Access Manager: vulnerabilidades y CVE
Microfocus Access Manager tiene 18 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses2
Críticas0
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-22506 | Alta (7.5) | 26% | ⚠ Explotación activa | 26 mar 2021 | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-11878 | Alta (8.2) | 0.22% | — | 24 jun 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2. |
| CVE-2026-11877 | Media (6.3) | 0.30% | — | 24 jun 2026 | An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3. |
| CVE-2021-22531 | Media (6.1) | 0.56% | — | 12 may 2022 | A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0 |
| CVE-2021-22528 | Media (5.4) | 0.58% | — | 13 sept 2021 | Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 |
| CVE-2021-22527 | Alta (7.5) | 0.73% | — | 13 sept 2021 | Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 |
| CVE-2021-22526 | Media (6.1) | 0.48% | — | 13 sept 2021 | Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 |
| CVE-2021-22524 | Media (4.9) | 0.65% | — | 13 sept 2021 | Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 |
| CVE-2021-22525 | Media (5.5) | 0.24% | — | 2 sept 2021 | This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1 |
| CVE-2021-22506 | Alta (7.5) | 26% | ⚠ Explotación activa | 26 mar 2021 | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage. |
| CVE-2020-25840 | Media (6.1) | 0.61% | — | 26 mar 2021 | Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction. |
| CVE-2021-22496 | Alta (7.5) | 1.1% | — | 25 mar 2021 | Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage. |
| CVE-2018-17948 | Media (6.1) | 0.65% | — | 20 nov 2018 | An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3. |
| CVE-2018-12480 | Media (6.1) | 0.65% | — | 15 nov 2018 | Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3. |
| CVE-2014-9412 | Media (4.3) | 3.2% | — | 23 dic 2014 | Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter to roma/jsp/debug/debug.jsp… |
| CVE-2014-5217 | Media (6.8) | 1.4% | — | 23 dic 2014 | Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentication of… |
| CVE-2014-5216 | Media (4.3) | 3.2% | — | 23 dic 2014 | Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web script or HTML via (1) the location parameter in a dev.Empty action… |
| CVE-2014-5215 | Media (4) | 1.8% | — | 23 dic 2014 | NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated administrators to discover service-account passwords via a request to (1) roma/jsp/volsc/monitoring/dev_services.jsp or (2)… |
| CVE-2014-5214 | Media (4) | 1.9% | — | 23 dic 2014 | nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Microfocus
Imanager · 22Solutions Business Manager · 17Edirectory · 16Service Manager · 16Enterprise Server · 12Enterprise Developer · 12Netiq Advanced Authentication · 11Application Automation Tools · 9Arcsight Logger · 9Arcsight Enterprise Security Manager · 8Arcsight Management Center · 8Operations Agent · 7