Skip to main content

Vendor/product archive

microfocus / imanager CVEs

Beta · best-effort

22 CVEs tagged to microfocus / imanager0 Critical, 12 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2023-24466

Published Nov 22, 2024

Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26324

Published Nov 22, 2024

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38134

Published Nov 22, 2024

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38119

Published Nov 22, 2024

Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38118

Published Nov 22, 2024

Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38116

Published Nov 22, 2024

Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11859

Published Nov 6, 2024

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4429

Published May 28, 2024

Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-3969

Published May 28, 2024

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3970

Published May 15, 2024

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3968

Published May 15, 2024

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3967

Published May 15, 2024

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3488

Published May 15, 2024

File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-3487

Published May 15, 2024

Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-3486

Published May 15, 2024

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3485

Published May 15, 2024

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3484

Published May 15, 2024

Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3483

Published May 15, 2024

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1