CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “microfocus”

223 vulnerabilities found for “microfocus”

Page 1 of 12

CVE-2020-11850
HIGH7.3

Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Password Reset before 4.5.0.2 and 4.4.0.6

microfocus / netiq_self_service_password_reset+8
Network
Published Aug 21, 2024
Page 1 of 12
CVE-2023-4964
HIGH8.2

Potential open redirect vulnerability in opentext Service Management Automation X (SMAX) versions 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset Management X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11. The vulnerability could allow attackers to redirect a user to malicious websites.

microfocus / asset_management_x+12
Network
Published Oct 30, 2023
CVE-2023-32265
HIGH7.1

A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this vulnerability. As described in the hardening guide in the product documentation, other mitigations including restricting network access to ESCWA and restricting users’ permissions in the Micro Focus Directory Server also reduce the exposure to this issue. Given the right conditions this vulnerability could be exploited to expose a service account password. The account corresponding to the exposed credentials usually has limited privileges and, in many cases would only be useful for extracting details of other user accounts and similar information.

microfocus / cobol_server+14
Network
Published Jul 20, 2023
CVE-2021-22531
MEDIUM6.1

A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0

microfocus / access_manager+14
Network
Published May 12, 2022
CVE-2021-22535
MEDIUM4.9

Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.

microfocus / netiq_directory_and_resource_administrator
Network
Published Sep 28, 2021
CVE-2021-22527
MEDIUM6.0

Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

microfocus / access_manager+1
Network
Published Sep 13, 2021
CVE-2021-22524
MEDIUM5.4

Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

microfocus / access_manager+1
Network
Published Sep 13, 2021
CVE-2021-22526
MEDIUM4.9

Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

microfocus / access_manager+1
Network
Published Sep 13, 2021
CVE-2021-22528
HIGH8.0

Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

microfocus / access_manager+1
Network
Published Sep 13, 2021
CVE-2021-22525
MEDIUM5.5

This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1

microfocus / access_manager
Local
Published Sep 2, 2021
CVE-2021-22516
HIGH7.5

Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulnerability could lead to sensitive information being in a log file.

microfocus / secure_api_manager
Network
Published Jun 4, 2021
CVE-2021-22506
HIGH7.5

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

microfocus / access_manager
Network
Published Mar 26, 2021
CVE-2020-25840
MEDIUM6.1

Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction.

microfocus / access_manager
Network
Published Mar 26, 2021
CVE-2021-22496
HIGH7.5

Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.

microfocus / access_manager
Network
Published Mar 25, 2021
CVE-2020-25833
MEDIUM4.8

Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. The vulnerability could be exploited to perform Persistent XSS attack.

microfocus / idol
Network
Published Nov 17, 2020
CVE-2019-11674
MEDIUM5.9

Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.

microfocus / netiq_self_service_password_reset+4
Network
Published Oct 22, 2019
CVE-2019-11652
CRITICAL9.8

A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate.

microfocus / netiq_self_service_password_reset+2
Network
Published Aug 14, 2019
CVE-2019-11647
MEDIUM6.1

A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.

microfocus / netiq_self_service_password_reset
Network
Published Jun 24, 2019
CVE-2018-17948
MEDIUM6.1

An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.

microfocus / access_manager+3
Network
Published Nov 20, 2018
CVE-2018-12480
MEDIUM6.1

Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.

microfocus / access_manager+7
Network
Published Nov 15, 2018