Lucene search

K
cveMicrofocusCVE-2020-11854
HistoryOct 27, 2020 - 5:15 p.m.

CVE-2020-11854

2020-10-2717:15:12
CWE-798
microfocus
web.nvd.nist.gov
74
2
cve-2020-11854
operation bridge manager
application performance management
operations bridge
micro focus
vulnerability
code execution

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.238

Percentile

96.7%

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

Affected configurations

Nvd
Node
microfocusapplication_performance_managementMatch9.50
OR
microfocusapplication_performance_managementMatch9.51
OR
microfocusoperations_bridgeMatch2017.11
OR
microfocusoperations_bridgeMatch2018.02
OR
microfocusoperations_bridgeMatch2018.05
OR
microfocusoperations_bridgeMatch2018.08
OR
microfocusoperations_bridgeMatch2018.11
OR
microfocusoperations_bridgeMatch2019.05
OR
microfocusoperations_bridgeMatch2019.08
OR
microfocusoperations_bridgeMatch2020.05
OR
microfocusoperations_bridge_managerRange10.10
OR
microfocusoperations_bridge_managerMatch10.11
OR
microfocusoperations_bridge_managerMatch10.12
OR
microfocusoperations_bridge_managerMatch10.60
OR
microfocusoperations_bridge_managerMatch10.61
OR
microfocusoperations_bridge_managerMatch10.62
OR
microfocusoperations_bridge_managerMatch10.63
OR
microfocusoperations_bridge_managerMatch2018.05
OR
microfocusoperations_bridge_managerMatch2018.11
OR
microfocusoperations_bridge_managerMatch2019.05
OR
microfocusoperations_bridge_managerMatch2019.11
OR
microfocusoperations_bridge_managerMatch2020.05
Node
microfocusapplication_performance_managementMatch9.40
OR
microfocusuniversal_cmdbMatch10.33cumulative_update_package_3
VendorProductVersionCPE
microfocusapplication_performance_management9.50cpe:2.3:a:microfocus:application_performance_management:9.50:*:*:*:*:*:*:*
microfocusapplication_performance_management9.51cpe:2.3:a:microfocus:application_performance_management:9.51:*:*:*:*:*:*:*
microfocusoperations_bridge2017.11cpe:2.3:a:microfocus:operations_bridge:2017.11:*:*:*:*:*:*:*
microfocusoperations_bridge2018.02cpe:2.3:a:microfocus:operations_bridge:2018.02:*:*:*:*:*:*:*
microfocusoperations_bridge2018.05cpe:2.3:a:microfocus:operations_bridge:2018.05:*:*:*:*:*:*:*
microfocusoperations_bridge2018.08cpe:2.3:a:microfocus:operations_bridge:2018.08:*:*:*:*:*:*:*
microfocusoperations_bridge2018.11cpe:2.3:a:microfocus:operations_bridge:2018.11:*:*:*:*:*:*:*
microfocusoperations_bridge2019.05cpe:2.3:a:microfocus:operations_bridge:2019.05:*:*:*:*:*:*:*
microfocusoperations_bridge2019.08cpe:2.3:a:microfocus:operations_bridge:2019.08:*:*:*:*:*:*:*
microfocusoperations_bridge2020.05cpe:2.3:a:microfocus:operations_bridge:2020.05:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CNA Affected

[
  {
    "product": "Application Performance Management ",
    "vendor": "Micro Focus ",
    "versions": [
      {
        "status": "affected",
        "version": "9.51"
      },
      {
        "status": "affected",
        "version": "9.50"
      },
      {
        "status": "affected",
        "version": "9.40"
      }
    ]
  },
  {
    "product": "Operation Bridge (containerized)",
    "vendor": "Micro Focus ",
    "versions": [
      {
        "status": "affected",
        "version": "2020.05"
      },
      {
        "status": "affected",
        "version": "2019.08"
      },
      {
        "status": "affected",
        "version": "2019.05"
      },
      {
        "status": "affected",
        "version": "2018.11"
      },
      {
        "status": "affected",
        "version": "2018.08"
      },
      {
        "status": "affected",
        "version": "2018.05"
      },
      {
        "status": "affected",
        "version": "2018.02"
      },
      {
        "status": "affected",
        "version": "2017.11"
      }
    ]
  },
  {
    "product": "Operation Bridge Manager",
    "vendor": "Micro Focus ",
    "versions": [
      {
        "status": "affected",
        "version": "2020.05"
      },
      {
        "status": "affected",
        "version": "2019.11"
      },
      {
        "status": "affected",
        "version": "2019.05"
      },
      {
        "status": "affected",
        "version": "2018.11"
      },
      {
        "status": "affected",
        "version": "2018.05"
      },
      {
        "status": "affected",
        "version": "10.63"
      },
      {
        "status": "affected",
        "version": "10.62"
      },
      {
        "status": "affected",
        "version": "10.61"
      },
      {
        "status": "affected",
        "version": "10.60"
      },
      {
        "status": "affected",
        "version": "10.12"
      },
      {
        "status": "affected",
        "version": "10.11"
      },
      {
        "lessThanOrEqual": "10.10",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.238

Percentile

96.7%