Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html | Exploit Third Party Advisory VDB Entry |
https://softwaresupport.softwaregrp.com/doc/KM03775947 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-153/ | Third Party Advisory VDB Entry |
https://www.zerodayinitiative.com/advisories/ZDI-21-154/ | Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html | Exploit Third Party Advisory VDB Entry |
https://softwaresupport.softwaregrp.com/doc/KM03775947 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-153/ | Third Party Advisory VDB Entry |
https://www.zerodayinitiative.com/advisories/ZDI-21-154/ | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 05:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry |
25 Jul 2024, 17:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry |
07 Nov 2023, 03:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - | |
References | () https://softwaresupport.softwaregrp.com/doc/KM03775947 - | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - | |
References | () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - |
Information
Published : 2021-02-08 22:15
Updated : 2024-11-21 05:50
NVD link : CVE-2021-22502
Mitre link : CVE-2021-22502
CVE.ORG link : CVE-2021-22502
JSON object : View
Products Affected
microfocus
- operation_bridge_reporter
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')