OpenText (formerly Micro Focus)
Self-Reporting Analysis
Of all the CVEs published by OpenText (formerly Micro Focus) as a CNA, 6.3% affect products that OpenText (formerly Micro Focus) develops as a vendor.
Of all the CVEs published that affect products developed by OpenText (formerly Micro Focus), 30.2% are self-published by OpenText (formerly Micro Focus) as a CNA.
Trends Over Time
The number and severity of CVEs published by OpenText (formerly Micro Focus) over time
Top CVEs
All CVEs published by OpenText (formerly Micro Focus) as a CNA, regardless of affected vendor or product.
606 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22502CRITICAL Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execu | Feb 8, 2021 | 9.8 | 98 | YES | YES |
CVE-2018-12464CRITICAL A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbit | Jun 29, 2018 | 9.8 | 87 | NO | YES |
CVE-2015-0779HIGH Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a | Jun 7, 2015 | 10.0 | 86 | NO | YES |
CVE-2020-11854CRITICAL Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products pr | Oct 27, 2020 | 9.8 | 85 | NO | YES |
CVE-2020-11853HIGH Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, version | Oct 22, 2020 | 8.8 | 84 | NO | YES |
CVE-2018-12465HIGH An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user | Jun 29, 2018 | 7.2 | 83 | NO | YES |
CVE-2021-22506HIGH Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause inf | Mar 26, 2021 | 7.5 | 75 | YES | NO |
CVE-2016-1593HIGH Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitra | Apr 22, 2016 | 7.2 | 71 | NO | YES |
CVE-2016-1606CRITICAL Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName propert | Jul 3, 2016 | 9.8 | 68 | NO | YES |
CVE-2015-6834CRITICAL Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to ( | May 16, 2016 | 9.8 | 60 | NO | YES |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (606 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by OpenText (formerly Micro Focus) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by OpenText (formerly Micro Focus) as a CNA — matched by CVE ID, not by organization name.