CVE-2021-22504

EUVD-2021-9650
Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could allow remote attackers to execute arbitrary code on an OBM server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
microfocusoperations_bridge_manager
10.10
microfocusoperations_bridge_manager
10.11
microfocusoperations_bridge_manager
10.12
microfocusoperations_bridge_manager
10.60
microfocusoperations_bridge_manager
10.61
microfocusoperations_bridge_manager
10.62
microfocusoperations_bridge_manager
10.63
microfocusoperations_bridge_manager
2018.05
microfocusoperations_bridge_manager
2018.11
microfocusoperations_bridge_manager
2019.05
microfocusoperations_bridge_manager
2019.11
microfocusoperations_bridge_manager
2020.05
microfocusoperations_bridge_manager
2020.10
𝑥
= Vulnerable software versions