CVE-2017-7420

CVE-2017-7420

Vendor Micro Focus
Product Micro Focus Enterprise Developer, Micro Focus Enterprise Server
Weakness CWE-287 · Improper authentication
Published August 21, 2017
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration information and alter the state of the running product (CWE-275).

Key dates

02Disclosure timeline

August 21, 2017 CVE published
September 16, 2024 Record updated