CVE-2021-22502

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microfocus:operation_bridge_reporter:10.40:*:*:*:*:*:*:*

History

21 Nov 2024, 05:50

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry
References () https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory () https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry
References () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry

25 Jul 2024, 17:52

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry
References () https://softwaresupport.softwaregrp.com/doc/KM03775947 - () https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry
References () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry

07 Nov 2023, 03:30

Type Values Removed Values Added
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ -
References (MISC) https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory () https://softwaresupport.softwaregrp.com/doc/KM03775947 -
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ -
References (MISC) http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html -

Information

Published : 2021-02-08 22:15

Updated : 2024-11-21 05:50


NVD link : CVE-2021-22502

Mitre link : CVE-2021-22502

CVE.ORG link : CVE-2021-22502


JSON object : View

Products Affected

microfocus

  • operation_bridge_reporter
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')