VendorsMicro Focusedirectoryall versions
Vulnerabilities

Micro Focus eDirectory

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2012-0432
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.
Published 2012-12-25 · Modified
10.02 PoCEPSS 0.587
CVE-2017-9285
Login restrictions not applied when using ebaclient against NetIQ eDirectory EBA interface
Published 2018-03-02 · Modified
9.8EPSS 0.012
CVE-2021-38132
Possible External service interaction Vulnerability
Published 2024-09-12 · Analyzed
9.8EPSS 0.004
CVE-2021-22533
Possible Insertion of Sensitive Information into Log File Vulnerability
Published 2024-09-12 · Analyzed
9.1EPSS 0.004
CVE-2017-7429
Fix for NetIQ shell code upload
Published 2018-03-02 · Modified
8.8EPSS 0.008
CVE-2021-22532
Possible NLDAP Denial of Service attack Vulnerability
Published 2024-09-12 · Analyzed
7.6EPSS 0.004
CVE-2018-7686
Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.
Published 2018-08-09 · Modified
7.5EPSS 0.014
CVE-2018-17950
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
Published 2018-12-12 · Modified
7.5EPSS 0.008
CVE-2021-38133
Possible Improper authentication Vulnerability in OpenText eDirectory
Published 2024-09-12 · Analyzed
7.4EPSS 0.003
CVE-2012-0430
Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors.
Published 2012-12-25 · Modified
6.4EPSS 0.022
CVE-2018-7692
Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.
Published 2018-08-09 · Modified
6.1EPSS 0.006
CVE-2018-17952
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
Published 2018-12-12 · Modified
6.1EPSS 0.006
CVE-2021-22503
Improper Neutralization of Input During Web Page Generation Vulnerability
Published 2024-09-12 · Analyzed
6.1EPSS 0.002
CVE-2021-38131
Cross-Site Scripting (XSS) Vulnerability
Published 2024-09-12 · Analyzed
6.1EPSS 0.002
CVE-2012-0428
Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2012-12-25 · Modified
4.3EPSS 0.018
CVE-2012-0429
dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request.
Published 2012-12-25 · Modified
4.0EPSS 0.019