Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18942PUBLISHED: 2021-02-26Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.
CVE-2019-18943PUBLISHED: 2021-02-26Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.
CVE-2019-18944PUBLISHED: 2021-02-26Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.
CVE-2019-18945PUBLISHED: 2021-02-26Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability.
CVE-2019-18946PUBLISHED: 2021-02-26Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixation.
User Rank: Ninja
1/24/2019 | 6:48:02 AM
Update - generally it was always a question of $$ as opposed to everything IS WORKING - why do we need to replace? Tech answers are not understood.