cbcvebase.

Microfocus Enterprise Server vulnerabilities

12 known vulnerabilities affecting microfocus/enterprise_server.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2017-7420P2CRITICALCVSS 9.8≤ 2.3v2.32017-08-21
CVE-2017-7420 [CRITICAL] CWE-287 CVE-2017-7420: An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration information and alter the state of the
nvd
CVE-2023-4501P2CRITICALCVSS 9.8v7.0v8.0+1 more2023-09-12
CVE-2023-4501 [CRITICAL] CWE-253 CVE-2023-4501: User authentication with username and password credentials is ineffective in OpenText (Micro Focus) User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1, when LDAP-based authentication
nvd
CVE-2020-9523P3HIGHCVSS 8.8≤ 3.0v4.0+1 more2020-04-17
CVE-2020-9523 [HIGH] CWE-522 CVE-2020-9523: Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterpris Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary sit
nvd
CVE-2017-7423P3HIGHCVSS 8.8v2.32017-08-21
CVE-2017-7423 [HIGH] CWE-352 CVE-2017-7423: A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Develo A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is configured. This includes creating new privileged credentials, resulting in privi
nvd
CVE-2017-7424P3MEDIUMCVSS 6.5v2.32017-08-21
CVE-2017-7424 [MEDIUM] CWE-22 CVE-2017-7424: A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enter A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to download arbitrary files from a system running the product, if this component is configured. Note esfadmingui is not enabled by default.
nvd
CVE-2017-5187P3HIGHCVSS 8.8≤ 2.3v2.32017-08-21
CVE-2017-5187 [HIGH] CWE-352 CVE-2017-5187: A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Admi A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter (CWE-275) configuration information and
nvd
CVE-2023-32265P3MEDIUMCVSS 6.5v6.0v7.0+1 more2023-07-20
CVE-2023-32265 [MEDIUM] CVE-2023-32265: A potential security vulnerability has been identified in the Enterprise Server Common Web Administ A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this vulnerability. As described in the hardening guide
nvd
CVE-2018-12469P4HIGHCVSS 7.5≤ 2.3v2.3+2 more2018-10-12
CVE-2018-12469 [HIGH] CWE-476 CVE-2018-12469: Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterp Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service
nvd
CVE-2017-7421P4MEDIUMCVSS 6.1≤ 2.3v2.32017-08-21
CVE-2017-7421 [MEDIUM] CWE-79 CVE-2017-7421: Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Ent Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticat
nvd
CVE-2019-11651P4MEDIUMCVSS 6.1v3.0v4.0+1 more2019-10-02
CVE-2019-11651 [MEDIUM] CWE-79 CVE-2019-11651: Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to versi Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, version 4.0 Patch Update 12, and version 5.0 Patch Update 2. The vulnerability could be exploited to redirect a user to a malicious page or forge certain types of web requests.
nvd
CVE-2020-9524P4MEDIUMCVSS 5.4v5.02020-05-18
CVE-2020-9524 [MEDIUM] CWE-79 CVE-2020-9524: Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affect Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).
nvd
CVE-2017-7422P4MEDIUMCVSS 5.4v2.32017-08-21
CVE-2017-7422 [MEDIUM] CWE-79 CVE-2017-7422: Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focu Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to bypass protection mechanisms (CWE-693) and other security features, if this component is configured.
nvd
Microfocus Enterprise Server vulnerabilities | cvebase