Junglewise Threat Intelligence

CVE-2021-22502: Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

CVE-2021-22502 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Executive brief

Micro Focus Operation Bridge Reporter (OBR) version 10.40 contains an OS command injection vulnerability (CWE-78) that allows an unauthenticated remote attacker to execute arbitrary code on the OBR server. The vulnerability is exploited via the network without requiring user interaction.

Affected products

  • Micro Focus Operation Bridge Reporter (OBR) 10.40

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: NVD publication date