CRITICAL

CVE-2021-22502

Microfocus Operation Bridge Reporter 2021-02-08 CVSS v3.1
CVSS
9.8
KEV

Description

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

Summary dbcve.org

Micro Focus Operation Bridge Reporter (OBR) version 10.40 contains a Remote Code Execution vulnerability that allows attackers to execute arbitrary code on the OBR server. The critical CVSS score of 9.8 indicates the vulnerability is easily exploitable over the network without authentication.

Mitigation

Upgrade OBR to a patched version if available, or contact Micro Focus for vendor-supplied remediation guidance. Implement network segmentation and restrict access to the OBR management interfaces until a fix is applied.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

96.74%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE