CVE-2019-11674: Micro Focus Netiq Self Service Password Reset

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.

Affected products

  • Micro Focus Netiq Self Service Password Reset: up to and including 4.3; version 4.4 only

Published 2019-10-22. Last modified 2026-06-17.