CRITICAL
CVE-2021-22502
CVSS
9.8
KEV
Description
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
Summary dbcve.org
Micro Focus Operation Bridge Reporter (OBR) version 10.40 contains a Remote Code Execution vulnerability that allows attackers to execute arbitrary code on the OBR server. The critical CVSS score of 9.8 indicates the vulnerability is easily exploitable over the network without authentication.
Mitigation
Upgrade OBR to a patched version if available, or contact Micro Focus for vendor-supplied remediation guidance. Implement network segmentation and restrict access to the OBR management interfaces until a fix is applied.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
96.74%
Probability of exploitation in next 30 days
99.9th percentile
References
http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html
Exploit, Third Party Advisory, VDB Entry
https://softwaresupport.softwaregrp.com/doc/KM03775947
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-153/
Third Party Advisory, VDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-21-154/
Third Party Advisory, VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22502
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.