VulnerabilityAnalyzed
CVE-2021-22506
Micro Focus Access Manager Information Leakage Vulnerability
KEVHIGH 7.5EPSS 25.7%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 25.70% probability · 98th percentile
- CISA KEV
- Listed 3 November 2021 · due 17 November 2021
- Affected
- microfocus/access manager
- Source
- security@opentext.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22506
References
- https://www.microfocus.com/documentation/access-manager/5.0/accessmanager50-release-notes/accessmanager50-release-notes.htmlRelease Notes
- https://www.microfocus.com/documentation/access-manager/5.0/accessmanager50-release-notes/accessmanager50-release-notes.htmlRelease Notes
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22506US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.