CVE-2021-22502
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 97% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-78
מוצרים מושפעים
microfocus: operation bridge reporter
קישורים
- https://softwaresupport.softwaregrp.com/doc/KM03775947 Vendor Advisory
- https://softwaresupport.softwaregrp.com/doc/KM03775947 Vendor Advisory
- http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Repo… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Repo… ExploitThird Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-21-153/ Third Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-21-154/ Third Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-21-153/ Third Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-21-154/ Third Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource