🔙 목록으로 돌아가기

CVE-2020-11853: Micro Focus Operations Bridge Manager <=2020.05 - Remote Code Execution

TitleMicro Focus Operations Bridge Manager <=2020.05 - Remote Code Execution
Authordwisiswant0
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patch or upgrade to a non-vulnerable version of Micro Focus Operations Bridge Manager.
CVSS Score8.8
EPSS Score0.92549
CVE IDCVE-2020-11853
Tags cve cve2020 opm rce packetstorm microfocus vuln

🔍 Vulnerability Description

Micro Focus Operations Bridge Manager in versions 2020.05 and below is vulnerable to remote code execution via UCMDB. The vulnerability allows remote attackers to execute arbitrary code on affected installations of Data Center Automation. An attack requires network access and authentication as a valid application user. Originated from Metasploit module (#14654).

🌐 HTTP Request

GET /ucmdb-api/connect HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11853.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-11853.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A