Micro Focus Vulnerabilities

Timeline

The analysis of the timeline helps to identify the required approach and handling of single vulnerabilities and vulnerability collections. This overview makes it possible to see less important slices and more severe hotspots at a glance. Initiating immediate vulnerability response and prioritizing of issues is possible.

Type

The moderation team is working with the threat intelligence team to categorize software that is affected by security vulnerabilities. This helps to illustrate the assignment of these categories to determine the most affected software types.

Product

Micro Focus Service Manager14
Micro Focus Arcsight Logger13
Micro Focus Enterprise Server11
Micro Focus Enterprise Developer11
Micro Focus Solutions Business Manager10

Grouping vulnerabilities by products helps to get an overview. This makes it possible to determine an homogeneous landscape or the most important hotspots in heterogeneous landscapes.

Remediation

Official Fix80
Temporary Fix0
Workaround0
Unavailable0
Not Defined91

Vendors and researchers are eager to find countermeasures to mitigate security vulnerabilities. These can be distinguished between multiple forms and levels of remediation which influence risks differently.

Exploitability

High5
Functional1
Proof-of-Concept12
Unproven0
Not Defined153

Researcher and attacker which are looking for security vulnerabilities try to exploit them for academic purposes or personal gain. The level and quality of exploitability can be distinguished to determine simplicity and strength of attacks.

Access Vector

Not Defined0
Physical0
Local8
Adjacent18
Network145

The approach a vulnerability it becomes important to use the expected access vector. This is typically via the network, local, or physically even.

Authentication

Not Defined0
High6
Low89
None76

To exploit a vulnerability a certail level of authentication might be required. Vulnerabilities without such a requirement are much more popular.

User Interaction

Not Defined0
Required53
None118

Some attack scenarios require some user interaction by a victim. This is typical for phishing, social engineering and cross site scripting attacks.

C3BM Index

Our unique C3BM Index (CVSSv3 Base Meta Index) cumulates the CVSSv3 Meta Base Scores of all entries over time. Comparing this index to the amount of disclosed vulnerabilities helps to pinpoint the most important events.

CVSSv3 Base

≤10
≤20
≤31
≤412
≤526
≤638
≤737
≤830
≤921
≤106

The Common Vulnerability Scoring System (CVSS) is an industry standard to define the characteristics and impacts of security vulnerabilities. The base score represents the intrinsic aspects that are constant over time and across user environments. Our unique meta score merges all available scores from different sources to aggregate to the most reliable result.

CVSSv3 Temp

≤10
≤20
≤31
≤417
≤523
≤636
≤740
≤828
≤921
≤105

The Common Vulnerability Scoring System (CVSS) uses temp scores to reflect the characteristics of a vulnerability that may change over time but not across user environments. This includes reporting confidence, exploitability and remediation levels. We do also provide our unique meta score for temp scores, even though other sources rarely publish them.

VulDB

≤10
≤21
≤32
≤433
≤529
≤635
≤729
≤833
≤93
≤106

The moderation team is always defining the base vector and base score for an entry. These and all other available scores are used to generate the meta score.

NVD

≤10
≤20
≤30
≤40
≤59
≤618
≤732
≤834
≤916
≤1027

The National Vulnerability Database (NVD) is also defining CVSS vectors and scores. These are usually not complete and might differ from VulDB scores.

CNA

≤10
≤20
≤32
≤41
≤52
≤65
≤79
≤89
≤94
≤104

A CVE Numbering Authority (CNA) is responsible for assigning new CVE entries. They might also include a CVSS score. These are usually not complete and might differ from VulDB scores.

Vendor

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

Some vendors are willing to publish their own CVSS vectors and scores for vulnerabilities in their products. The coverage varies from vendor to vendor.

Research

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

There are sometimes also security researcher which provide their own CVSS vectors and scores for vulnerabilities they have found and published.

Exploit 0-day

<1k49
<2k78
<5k44
<10k0
<25k0
<50k0
<100k0
≥100k0

The moderation team is working with the threat intelligence team to determine prices for exploits. Our unique algorithm is used to identify the 0-day prices for an exploit, before it got distributed or became public. Calculated prices are aligned to prices disclosed by vulnerability broker and compared to prices we see on exploit markets.

Exploit Today

<1k166
<2k5
<5k0
<10k0
<25k0
<50k0
<100k0
≥100k0

The 0-day prices do not consider time-relevant factors. The today price does reflect price impacts like disclosure of vulnerability details, alternative exploits, availability of countermeasures. These dynamic aspects might decrease the exploit prices over time. Under certain circumstances this happens very fast.

Exploit Market Volume

Our unique calculation of exploit prices makes it possible to forecast the expected exploit market volume. The calculated prices for all possible 0-day expoits are cumulated for this task. Comparing the volume to the amount of disclosed vulnerabilities helps to pinpoint the most important events.

🔴 CTI Activities

Our unique Cyber Threat Intelligence aims to determine the ongoing research of actors to anticipiate their acitivities. Observing exploit markets on the Darknet, discussions of vulnerabilities on mailinglists, and exchanges on social media makes it possible to identify planned attacks. Monitored actors and activities are classified whether they are offensive or defensive. They are also weighted as some actors are well-known for certain products and technologies. And some of their disclosures might contain more or less details about technical aspects and personal context. The world map highlights active actors in real-time.

Affected Products (82): Access Manager (3), AcuToWeb (1), Application Lifecycle Management (1), Application Performance Management (4), ArcSight Enterprise Security Manager (4), ArcSight Logger (4), ArcSight Management Center (6), Arcsight Logger (13), Business Manager (5), CMS (1), COBOL Server (1), Client for OES (1), Content Manager (3), Data Center Automation Containerized Suite (2), Data Protector (3), Dimensions CM Plugin (1), Dimensions Plugin (2), Directory and Resource Administrator (1), Enterprise Developer (11), Enterprise Server (11), Enterprise Test Server (1), Filr (5), Fortify Audit Workbench (1), Fortify Software Security Center (4), GroupWise (1), GroupWise Web (1), Host Access Management (1), Hybrid Cloud Management Containerized Suite (2), IDOL (1), Identity Manager (1), Manager (1), NetIQ (2), NetIQ Access Manager (3), Network Automation (2), Network Operations Management Suite (2), Novell Groupwise (3), Novell Service Desk (4), OpenText (1), Operation Agent (1), Operation Bridge (1), Operation Bridge Manager (1), Operation Bridge Reporter (4), Operation bridge Manager (1), Operations Agent (3), Operations Bridge (2), Operations Bridge Containerized (1), Operations Bridge Containerized Suite (3), Operations Bridge Manager (2), Operations Manager i (1), Operations Orchestration (1), Portfolio Management Center (3), Project (3), RUMBA (3), Real User Monitoring Software (1), Reflection Security Gateway (1), Reflection ZFE (1), Reflection for the Web (1), Rumba FTP (1), Secure API Manager (1), Secure Messaging Gateway (3), Security Server (1), Self Service Password Reset (3), Service Management Automation (1), Service Management Automation Suite (2), Service Manager (14), Service Manager Automation (1), Service Manager Chat Server (1), Service Manager Chat Service (1), Service Manager Release Control (1), SiteScope (1), Solution Business Manager (1), Solutions Business Manager (10), UCMDB Browser (1), Universal CMDB (3), Universal CMDB Foundation (1), Verastream Host Integrator (4), Vibe (2), VisiBroker (3), Visual COBOL (1), Voltage SecureMail Mail Relay (1), ZENworks (1), ZENworks Configuration Management (1)

Link to Vendor Website: https://www.microfocus.com/

PublishedBaseTempVulnerabilityProdExpRemEPSSCTICVE
12/09/20234.64.5Micro Focus ArcSight Management Center cross site scriptingUnknownNot DefinedOfficial Fix0.000450.04CVE-2020-25835
09/13/20239.89.6Micro Focus OpenText improper authenticationUnknownNot DefinedOfficial Fix0.000910.07CVE-2023-4501
08/11/20237.37.3Micro Focus ArcSight Management Center Privilege EscalationUnknownNot DefinedNot Defined0.000500.04CVE-2023-32267
07/20/20236.66.6Micro Focus Enterprise Server Enterprise Server Common Web Administration permissionUnknownNot DefinedNot Defined0.000490.00CVE-2023-32265
07/19/20233.83.8Micro Focus Dimensions CM Plugin certificate validationJenkins PluginNot DefinedNot Defined0.000490.00CVE-2023-32263
06/17/20233.53.4Micro Focus Dimensions Plugin permissionJenkins PluginNot DefinedOfficial Fix0.000660.04CVE-2023-32261
06/16/20233.53.5Micro Focus Dimensions Plugin information disclosureJenkins PluginNot DefinedNot Defined0.000660.00CVE-2023-32262
06/14/20234.84.7Micro Focus ArcSight Logger cross site scriptingLog Management SoftwareNot DefinedOfficial Fix0.000740.00CVE-2023-24469
06/14/20237.37.2Micro Focus ArcSight Logger xml external entity referenceLog Management SoftwareNot DefinedOfficial Fix0.000930.05CVE-2023-24470
12/23/20227.27.2Micro Focus ZENworks Managed Device privileges managementUnknownNot DefinedNot Defined0.001600.00CVE-2022-38757
12/17/20224.34.2Micro Focus GroupWise Web GW Web log fileUnknownNot DefinedOfficial Fix0.000790.03CVE-2022-38756
12/08/20225.65.6Micro Focus Operations Bridge Containerized cross site scriptingVirtualization SoftwareNot DefinedOfficial Fix0.000780.04CVE-2022-38754
11/21/20225.35.2Micro Focus Filr information disclosureUnknownNot DefinedOfficial Fix0.001290.00CVE-2022-38755
09/01/20225.25.2Micro Focus ArcSight Logger cross site scriptingLog Management SoftwareNot DefinedNot Defined0.000780.04CVE-2022-26331
09/01/20225.85.8Micro Focus ArcSight Logger cross site scriptingLog Management SoftwareNot DefinedNot Defined0.001580.02CVE-2022-26330
05/13/20223.53.5Micro Focus NetIQ Access Manager cross site scriptingAccess Management SoftwareNot DefinedNot Defined0.000720.03CVE-2021-22531
05/03/20222.42.4Micro Focus NetIQ Access Manager cross site scriptingAccess Management SoftwareNot DefinedOfficial Fix0.000720.06CVE-2022-26325
05/03/20223.93.9Micro Focus NetIQ Access Manager URL redirectAccess Management SoftwareNot DefinedOfficial Fix0.000720.05CVE-2022-26326
04/12/20227.37.3Micro Focus Operations Bridge Remote Code ExecutionUnknownNot DefinedNot Defined0.005250.00CVE-2021-38125
02/05/20223.53.4Micro Focus Voltage SecureMail Mail Relay information disclosureUnknownNot DefinedOfficial Fix0.000650.04CVE-2021-38130
01/26/20225.35.3Micro Focus Operations Agent Local Privilege EscalationUnknownNot DefinedNot Defined0.000420.04CVE-2021-38129
01/15/20223.53.5Micro Focus ArcSight Enterprise Security Manager cross site scriptingUnknownNot DefinedNot Defined0.000720.00CVE-2021-38127
01/15/20223.53.5Micro Focus ArcSight Enterprise Security Manager cross site scriptingUnknownNot DefinedNot Defined0.000720.00CVE-2021-38126
09/28/20214.34.1Micro Focus Directory and Resource Administrator information disclosureUnknownNot DefinedOfficial Fix0.000650.00CVE-2021-22535
09/28/20218.08.0Micro Focus ArcSight Enterprise Security Manager command injectionUnknownNot DefinedNot Defined0.011290.05CVE-2021-38124

146 more entries are not shown

Might our Artificial Intelligence support you?

Check our Alexa App!