Microfocus maintains a broadly represented portfolio spanning identity and access management, IT service management, and directory infrastructure products that are widely deployed across enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure concentrates in products such as iManager, Access Manager, eDirectory, and Service Manager and recurs through weakness classes including input-validation and neutralization failures (cross-site scripting, XML external entity injection), cross-site request forgery, and sensitive information exposure that are characteristic of web-facing authentication and administrative interfaces. Defenders should treat Microfocus advisories affecting identity and access control systems as high-priority given their direct bearing on account compromise and lateral movement risk. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microfocus over time
Signals from CVEs in this vendor scope (274 CVEs).
274 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22502CRITICAL Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execu | Feb 8, 2021 | 9.8 | 98 | YES | YES |
CVE-2019-5736HIGH runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi | Feb 11, 2019 | 8.6 | 91 | NO | YES |
CVE-2018-12464CRITICAL A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbit | Jun 29, 2018 | 9.8 | 87 | NO | YES |
CVE-2020-11854CRITICAL Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products pr | Oct 27, 2020 | 9.8 | 85 | NO | YES |
CVE-2020-11853HIGH Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, version | Oct 22, 2020 | 8.8 | 84 | NO | YES |
CVE-2018-12465HIGH An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user | Jun 29, 2018 | 7.2 | 83 | NO | YES |
CVE-2012-0432HIGH Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors. | Dec 25, 2012 | 10.0 | 81 | NO | YES |
CVE-2012-5932HIGH Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute | Dec 24, 2012 | 10.0 | 81 | NO | YES |
CVE-2021-22506HIGH Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause inf | Mar 26, 2021 | 7.5 | 75 | YES | NO |
CVE-2016-1606CRITICAL Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName propert | Jul 3, 2016 | 9.8 | 68 | NO | YES |
Signals from CVEs in this vendor scope (274 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microfocus.
Media articles that mention a CVE ID that affects a product developed by Microfocus — matched by CVE ID, not by vendor name.