An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user
References
Link | Resource |
---|---|
https://softwaresupport.softwaregrp.com/doc/KM03710590 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-20-1215/ | Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/162407/Micro-Focus-Operations-Bridge-Reporter-shrboadmin-Default-Password.html | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2020-09-22 07:15
Updated : 2021-04-30 16:39
NVD link : CVE-2020-11857
Mitre link : CVE-2020-11857
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
microfocus
- operation_bridge_reporter