Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
References
Link | Resource |
---|---|
https://softwaresupport.softwaregrp.com/doc/KM03775947 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-153/ | Third Party Advisory VDB Entry |
https://www.zerodayinitiative.com/advisories/ZDI-21-154/ | Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2021-02-08 14:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-22502
Mitre link : CVE-2021-22502
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
microfocus
- operation_bridge_reporter