PT-2020-12895 · Micro Focus · Service Management Automation+6

Published

2020-10-22

·

Updated

2022-11-16

·

CVE-2020-11853

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.6x, 10.1x and older versions Application Performance Management versions 9.51, 9.50, 9.40 with uCMDB 10.33 CUP 3 Data Center Automation version 2019.11 Operations Bridge (containerized) versions 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 Universal CMDB versions 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 Hybrid Cloud Management version 2020.05 Service Management Automation versions 2020.5, 2020.02
Description The issue is an arbitrary code execution vulnerability affecting multiple Micro Focus products. It could allow the execution of arbitrary code. The vulnerability is related to the deserialization of untrusted data in various services, including PackageFacadeForGui, LocationService, MultiTenancyService, WatchServerAPI, ImpactService, SAMDownloadServlet, ServiceDiscoveryService, MailService, CMSImagesService, GenericAdapterService, CITService, TopologyService, AutomationMappingService, FoldersFacade, RegistrationServlet, SnapshotService, BusinessModelFacadeForGui, DataAcquisitionService, BundleService, CategoryFacadeForGui, CIService, PatternService, CorrelationRunnerFacade, HistoryService, LicensingService, RelatedCIsService, ClassModelService, LDAPService, ResourceManagementService, SecurityService, PermissionsService, SchedulerFacadeForGui, SchedulerService, DiscoveryService, CmdbOperationExecuterService, CommonService, SoftwareLibraryService, CorrelationFacadeForGui, FolderService, ReportService.
Recommendations Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.6x, 10.1x and older versions: Update to a version that is not affected by this issue. Application Performance Management versions 9.51, 9.50, 9.40 with uCMDB 10.33 CUP 3: Update to a version that is not affected by this issue. Data Center Automation version 2019.11: Update to a version that is not affected by this issue. Operations Bridge (containerized) versions 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11: Update to a version that is not affected by this issue. Universal CMDB versions 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30: Update to a version that is not affected by this issue. Hybrid Cloud Management version 2020.05: Update to a version that is not affected by this issue. Service Management Automation versions 2020.5, 2020.02: Update to a version that is not affected by this issue. As a temporary workaround, consider disabling the deserialization of untrusted data in the affected services until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-11853
ZDI-20-1288
ZDI-20-1289
ZDI-20-1290
ZDI-20-1291
ZDI-20-1292
ZDI-20-1293
ZDI-20-1294
ZDI-20-1295
ZDI-20-1296
ZDI-20-1297
ZDI-20-1298
ZDI-20-1299
ZDI-20-1300
ZDI-20-1301
ZDI-20-1302
ZDI-20-1303
ZDI-20-1304
ZDI-20-1305
ZDI-20-1306
ZDI-20-1307
ZDI-20-1308
ZDI-20-1309
ZDI-20-1310
ZDI-20-1311
ZDI-20-1312
ZDI-20-1313
ZDI-20-1314
ZDI-20-1315
ZDI-20-1316
ZDI-20-1317
ZDI-20-1318
ZDI-20-1319
ZDI-20-1320
ZDI-20-1321
ZDI-20-1322
ZDI-20-1323
ZDI-20-1324
ZDI-20-1325
ZDI-20-1327
ZDI-20-1328

Affected Products

Ibm Application Performance Management
Data Center Automation
Hybrid Cloud Management
Operation Bridge Manager
Operations Bridge
Service Management Automation
Hp Universal Cmdb