CVE-2021-22506 KEV
7.5
HIGH · CVSS 3.1 · EPSS 25.7% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2021-11-17.
Description
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 25.7% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | yes — remediate by 2021-11-17 |
| Public exploit | none known |
| Published | 2021-03-26 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Micro Focus Access Manager Information Leakage Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2021-11-17 |
| Vendor / product | Micro Focus / Micro Focus Access Manager |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| microfocus | access manager |
References
- https://www.microfocus.com/documentation/access-manager/5.0/accessmanager50-release-notes/accessmanager50-release-notes.html
- https://www.microfocus.com/documentation/access-manager/5.0/accessmanager50-release-notes/accessmanager50-release-notes.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22506
→ the Explorer · watch your stack · NVD