PT-2020-6292 · Micro Focus · Operation Bridge Reporter

Pedrib1337

+1

·

Published

2020-09-30

·

Updated

2025-03-12

·

CVE-2021-22502

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Micro Focus Operation Bridge Reporter version 10.40
Description The issue is related to a Remote Code Execution vulnerability in the Micro Focus Operation Bridge Reporter product. It could be exploited to allow Remote Code Execution on the OBR server. The vulnerability is associated with incorrect handling of parameters in the LogonResource endpoint. This could enable a remote attacker to execute arbitrary code.
Recommendations For version 10.40, consider disabling the LogonResource endpoint or restricting access to it until a patch is available. Additionally, be cautious when using the userName and token parameters in the affected API endpoints to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04036
CVE-2021-22502
ZDI-21-153
ZDI-21-154

Affected Products

Operation Bridge Reporter