CVE-2021-22502 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 96.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2021-11-17.
Description
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 96.74% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2021-11-17 |
| Public exploit | none known |
| Published | 2021-02-08 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2021-11-17 |
| Vendor / product | Micro Focus / Operation Bridge Reporter (OBR) |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| microfocus | operation bridge reporter |
References
- http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html
- https://softwaresupport.softwaregrp.com/doc/KM03775947
- https://www.zerodayinitiative.com/advisories/ZDI-21-153/
- https://www.zerodayinitiative.com/advisories/ZDI-21-154/
- http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html
- https://softwaresupport.softwaregrp.com/doc/KM03775947
- https://www.zerodayinitiative.com/advisories/ZDI-21-153/
- https://www.zerodayinitiative.com/advisories/ZDI-21-154/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22502
→ the Explorer · watch your stack · NVD