SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-22506

Micro Focus Access Manager Information Leakage Vulnerability

KEVHIGH 7.5EPSS 25.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
25.70% probability · 98th percentile
CISA KEV
Listed 3 November 2021 · due 17 November 2021
Affected
microfocus/access manager
Source
security@opentext.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22506

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.