CVE-2021-22504

Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could allow remote attackers to execute arbitrary code on an OBM server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
microfocusCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
microfocusoperations_bridge_manager
10.10
microfocusoperations_bridge_manager
10.11
microfocusoperations_bridge_manager
10.12
microfocusoperations_bridge_manager
10.60
microfocusoperations_bridge_manager
10.61
microfocusoperations_bridge_manager
10.62
microfocusoperations_bridge_manager
10.63
microfocusoperations_bridge_manager
2018.05
microfocusoperations_bridge_manager
2018.11
microfocusoperations_bridge_manager
2019.05
microfocusoperations_bridge_manager
2019.11
microfocusoperations_bridge_manager
2020.05
microfocusoperations_bridge_manager
2020.10
𝑥
= Vulnerable software versions