CVE-2021-22502

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microfocus:operation_bridge_reporter:10.40:*:*:*:*:*:*:*

History

07 Nov 2023, 03:30

Type Values Removed Values Added
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ -
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ -
References (MISC) http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html -
References (MISC) https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory () https://softwaresupport.softwaregrp.com/doc/KM03775947 -

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-94 CWE-78

30 Apr 2021, 23:38

Type Values Removed Values Added
References (MISC) http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - (MISC) http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry

30 Apr 2021, 17:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html -

11 Feb 2021, 18:50

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
CPE cpe:2.3:a:microfocus:operation_bridge_reporter:10.40:*:*:*:*:*:*:*
References (MISC) https://softwaresupport.softwaregrp.com/doc/KM03775947 - (MISC) https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry

09 Feb 2021, 11:15

Type Values Removed Values Added
References
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-154/ -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-153/ -

08 Feb 2021, 22:19

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-08 22:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-22502

Mitre link : CVE-2021-22502

CVE.ORG link : CVE-2021-22502


JSON object : View

Products Affected

microfocus

  • operation_bridge_reporter
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')