Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
References
| Link | Resource |
|---|---|
| https://softwaresupport.softwaregrp.com/doc/KM03775947 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-153/ | Third Party Advisory VDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-21-154/ | Third Party Advisory VDB Entry |
| http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2021-02-08 14:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-22502
Mitre link : CVE-2021-22502
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
microfocus
- operation_bridge_reporter


