CVE-2020-11858

Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Bridge (containerized). The vulneravility affects: 1.) Operation Bridge Manager versions: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) versions: 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. The vulnerability could allow local attackers to execute code with escalated privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
microfocusCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
microfocusoperations_bridge
2017.11
microfocusoperations_bridge
2018.02
microfocusoperations_bridge
2018.05
microfocusoperations_bridge
2018.08
microfocusoperations_bridge
2018.11
microfocusoperations_bridge
2019.05
microfocusoperations_bridge
2019.08
microfocusoperations_bridge
2020.05
microfocusoperations_bridge_manager
𝑥
≤ 10.10
microfocusoperations_bridge_manager
10.11
microfocusoperations_bridge_manager
10.12
microfocusoperations_bridge_manager
10.60
microfocusoperations_bridge_manager
10.61
microfocusoperations_bridge_manager
10.62
microfocusoperations_bridge_manager
10.63
microfocusoperations_bridge_manager
2018.05
microfocusoperations_bridge_manager
2018.11
microfocusoperations_bridge_manager
2019.05
microfocusoperations_bridge_manager
2019.11
microfocusoperations_bridge_manager
2020.05
𝑥
= Vulnerable software versions