{
    "id": "CVE-2020-11856",
    "published": "2020-09-22 15:15:14",
    "last_modified": "2026-06-17 02:50:55",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-306",
    "description": "Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.",
    "epss_score": "0.05235",
    "epss_percentile": "0.92304",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-07 18:17:22",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "microfocus",
            "product": "operation_bridge_reporter"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://softwaresupport.softwaregrp.com/doc/KM03710590",
        "https://www.zerodayinitiative.com/advisories/ZDI-20-1216/",
        "https://softwaresupport.softwaregrp.com/doc/KM03710590",
        "https://www.zerodayinitiative.com/advisories/ZDI-20-1216/"
    ]
}