SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-22502

Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 96.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
96.74% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 17 November 2021
Weakness
CWE-78
Affected
microfocus/operation bridge reporter
Source
security@opentext.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22502

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.