peter bassill · operator
$ cve CVE-2021-22506 JSON

CVE-2021-22506 KEV

7.5
HIGH · CVSS 3.1 · EPSS 25.7% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2021-11-17.

Description

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS25.7% — more likely to be exploited than 98% of all CVEs
On CISA KEVyes — remediate by 2021-11-17
Public exploitnone known
Published2021-03-26
Last modified2026-06-17

CISA KEV

NameMicro Focus Access Manager Information Leakage Vulnerability
Added2021-11-03
Due2021-11-17
Vendor / productMicro Focus / Micro Focus Access Manager
Ransomware usenone reported

Affected (1)

VendorProduct
microfocusaccess manager

References

→ the Explorer  ·  watch your stack  ·  NVD