PT-2020-12896 · Micro Focus · Ibm Application Performance Management+2

Pedrib1337

+1

·

Published

2020-10-27

·

Updated

2022-04-26

·

CVE-2020-11854

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Operation Bridge Manager versions 2017.11 through 2020.05 Operations Bridge (containerized) versions 2017.11 through 2020.05 Application Performance Management versions 9.40 through 9.51
Description The issue affects Micro Focus products, including Operation Bridge Manager, Operations Bridge (containerized), and Application Performance Management. It could allow arbitrary code execution.
Recommendations For Operation Bridge Manager versions 2017.11 through 2020.05, update to a version later than 2020.05. For Operations Bridge (containerized) versions 2017.11 through 2020.05, update to a version later than 2020.05. For Application Performance Management versions 9.40 through 9.51, update to a version later than 9.51.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11854
ZDI-20-1287

Affected Products

Ibm Application Performance Management
Operation Bridge Manager
Operations Bridge