Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-18591


A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51. The vulnerability could be exploited to release unauthorized disclosure of data.


Published

2018-11-13T13:29:00.183

Last Modified

2024-11-21T03:56:13.143

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microfocus service_manager 9.30 Yes
Application microfocus service_manager 9.31 Yes
Application microfocus service_manager 9.32 Yes
Application microfocus service_manager 9.33 Yes
Application microfocus service_manager 9.34 Yes
Application microfocus service_manager 9.35 Yes
Application microfocus service_manager 9.40 Yes
Application microfocus service_manager 9.41 Yes
Application microfocus service_manager 9.50 Yes
Application microfocus service_manager 9.51 Yes

References