CVE-2019-11652: Micro Focus Netiq Self Service Password Reset

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate.

Affected products

  • Micro Focus Netiq Self Service Password Reset: from 4.2.0.0, before 4.2.0.6 (fixed in 4.2.0.6); from 4.3.0.0, before 4.3.0.6 (fixed in 4.3.0.6); from 4.4.0.0, before 4.4.0.3 (fixed in 4.4.0.3)

Published 2019-08-14. Last modified 2026-06-17.