Vulnerabilities (CVE)

Filtered by vendor Microfocus Subscribe
Filtered by product Solutions Business Manager
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-7680 1 Microfocus 1 Solutions Business Manager 2021-04-09 4.3 MEDIUM 6.1 MEDIUM
Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.
CVE-2018-7681 1 Microfocus 1 Solutions Business Manager 2021-04-09 3.5 LOW 4.8 MEDIUM
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system.
CVE-2018-7682 1 Microfocus 1 Solutions Business Manager 2021-04-09 4.0 MEDIUM 6.5 MEDIUM
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
CVE-2019-18946 1 Microfocus 1 Solutions Business Manager 2021-03-01 3.8 LOW 4.8 MEDIUM
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.
CVE-2019-18942 1 Microfocus 1 Solutions Business Manager 2021-03-01 2.3 LOW 4.8 MEDIUM
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.
CVE-2019-18944 1 Microfocus 1 Solutions Business Manager 2021-03-01 2.3 LOW 4.8 MEDIUM
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.
CVE-2018-19644 1 Microfocus 1 Solutions Business Manager 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
CVE-2019-3477 1 Microfocus 1 Solutions Business Manager 2019-06-10 5.8 MEDIUM 6.1 MEDIUM
Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.