VendorsMicro Focusnetiq_self_service_password_resetall versions
Vulnerabilities

Micro Focus NetIQ Self Service Password Reset

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-11652
A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate.
Published 2019-08-14 · Modified
9.8EPSS 0.021
CVE-2020-11850
Cross site scripting vulnerability in Self Service Password Reset
Published 2024-08-21 · Analyzed
7.3EPSS 0.003
CVE-2019-11647
A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.
Published 2019-06-24 · Modified
6.1EPSS 0.006
CVE-2019-11674
Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.
Published 2019-10-22 · Modified
5.9EPSS 0.004