threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microfocus enterprise developer
Product
microfocus enterprise developer
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-4501
all versions
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, En
9.8
CRITICAL
CVE-2023-32265
all versions
A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used i
7.1
HIGH
CVE-2020-9524
all versions
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to vers
5.4
MEDIUM
CVE-2020-9523
<= 3.0
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all versio
8.8
HIGH
CVE-2019-11651
all versions
Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, versio
6.1
MEDIUM
CVE-2018-12469
<= 2.3
Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web
7.5
HIGH
CVE-2017-7424
all versions
A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1
6.5
MEDIUM
CVE-2017-7423
all versions
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3,
8.8
HIGH
CVE-2017-7422
all versions
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Ent
5.4
MEDIUM
CVE-2017-7421
all versions
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration
6.1
MEDIUM
CVE-2017-7420
all versions
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise De
9.8
CRITICAL
CVE-2017-5187
all versions
A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Fo
8.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin