Skip to main content

Vendor archive

microfocus CVEs

Beta · best-effort

273 CVEs tagged to vendor microfocus40 Critical, 95 High, 128 Medium, 10 Low, 0 Unrated.

CVE-2026-11878

Published Jun 24, 2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affect…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-11877

Published Jun 24, 2026

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2123

Published Mar 31, 2026

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from sp…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-24466

Published Nov 22, 2024

Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26324

Published Nov 22, 2024

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38134

Published Nov 22, 2024

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38119

Published Nov 22, 2024

Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38118

Published Nov 22, 2024

Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38116

Published Nov 22, 2024

Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11859

Published Nov 6, 2024

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5532

Published Oct 28, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an att…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4692

Published Oct 16, 2024

Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4690

Published Oct 16, 2024

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automatio…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4211

Published Oct 16, 2024

Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4189

Published Oct 16, 2024

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automatio…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4184

Published Oct 16, 2024

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automatio…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6360

Published Oct 2, 2024

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica age…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38133

Published Sep 12, 2024

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38132

Published Sep 12, 2024

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38131

Published Sep 12, 2024

Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22533

Published Sep 12, 2024

Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 273 CVEsPage 1 of 11