OpenText (formerly Micro Focus)

First CVE: Nov 10, 2014Active for: 12 years
606
CVEs Published
More CVEs Published than 88% of tracked CNAs
46.6
Avg CVEs / Year
More Avg CVEs / Year than 83% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked CNAs
0.3%
In CISA KEV
Higher KEV Rate than 82% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by OpenText (formerly Micro Focus) as a CNA, 6.3% affect products that OpenText (formerly Micro Focus) develops as a vendor.

93.7%
Self-reported: 38Third-party: 568

Of all the CVEs published that affect products developed by OpenText (formerly Micro Focus), 30.2% are self-published by OpenText (formerly Micro Focus) as a CNA.

30.2%
69.8%
Self-published: 38Published by other CNAs: 88

Trends Over Time

The number and severity of CVEs published by OpenText (formerly Micro Focus) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2014
11 years ago
Most Recent CVE
Jun 24, 2026
30 days ago

Top CVEs

All CVEs published by OpenText (formerly Micro Focus) as a CNA, regardless of affected vendor or product.

606 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execu
Feb 8, 20219.898YESYES
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbit
Jun 29, 20189.887NOYES
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a
Jun 7, 201510.086NOYES
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products pr
Oct 27, 20209.885NOYES
Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, version
Oct 22, 20208.884NOYES
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user
Jun 29, 20187.283NOYES
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause inf
Mar 26, 20217.575YESNO
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitra
Apr 22, 20167.271NOYES
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName propert
Jul 3, 20169.868NOYES
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (
May 16, 20169.860NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA606 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local64 (10.6%)
Network518 (85.5%)
Unknown9 (1.5%)
Physical6 (1.0%)
Adjacent Network8 (1.3%)
Attack Complexity
Low563 (92.9%)
High34 (5.6%)
Unknown9 (1.5%)
User Interaction
None417 (68.8%)
Unknown9 (1.5%)
Required159 (26.2%)
Privileges Required
Low196 (32.3%)
High33 (5.4%)
None368 (60.7%)
Unknown9 (1.5%)

Exploit Exposure

Signals from CVEs in this cna scope (606 CVEs).

CISA KEV
2 CVEs
0.3% of CVEs· 82nd percentile
Metasploit
11 CVEs
1.8% of CVEs· 91st percentile
Nuclei
3 CVEs
0.5% of CVEs· 76th percentile
ExploitDB
30 CVEs
5.0% of CVEs· 95th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by OpenText (formerly Micro Focus) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by OpenText (formerly Micro Focus) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs