CVE-2020-11856

Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microfocus:operation_bridge_reporter:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:15

Type Values Removed Values Added
CWE CWE-862 CWE-306
References (MISC) https://softwaresupport.softwaregrp.com/doc/KM03710590 - Vendor Advisory () https://softwaresupport.softwaregrp.com/doc/KM03710590 -
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-20-1216/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-20-1216/ -

Information

Published : 2020-09-22 15:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-11856

Mitre link : CVE-2020-11856

CVE.ORG link : CVE-2020-11856


JSON object : View

Products Affected

microfocus

  • operation_bridge_reporter
CWE
CWE-306

Missing Authentication for Critical Function