Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-11853


Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.


Published

2020-10-22T21:15:12.747

Last Modified

2024-11-21T04:58:45.563

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microfocus operation_bridge_manager ≤ 10.10 Yes
Application microfocus operation_bridge_manager 10.11 Yes
Application microfocus operation_bridge_manager 10.12 Yes
Application microfocus operation_bridge_manager 10.60 Yes
Application microfocus operation_bridge_manager 10.61 Yes
Application microfocus operation_bridge_manager 10.62 Yes
Application microfocus operation_bridge_manager 10.63 Yes
Application microfocus operations_bridge_manager 2017.11 Yes
Application microfocus operations_bridge_manager 2018.02 Yes
Application microfocus operations_bridge_manager 2018.05 Yes
Application microfocus operations_bridge_manager 2018.08 Yes
Application microfocus operations_bridge_manager 2018.11 Yes
Application microfocus operations_bridge_manager 2019.05 Yes
Application microfocus operations_bridge_manager 2019.08 Yes
Application microfocus operations_bridge_manager 2019.11 Yes
Application microfocus operations_bridge_manager 2020.05 Yes
Application hp universal_cmbd_foundation 10.20 Yes
Application hp universal_cmbd_foundation 10.30 Yes
Application hp universal_cmbd_foundation 10.31 Yes
Application hp universal_cmbd_foundation 10.32 Yes
Application hp universal_cmbd_foundation 10.33 Yes
Application hp universal_cmbd_foundation 11.0 Yes
Application hp universal_cmbd_foundation 2018.05 Yes
Application hp universal_cmbd_foundation 2018.08 Yes
Application hp universal_cmbd_foundation 2018.11 Yes
Application hp universal_cmbd_foundation 2019.02 Yes
Application hp universal_cmbd_foundation 2019.05 Yes
Application hp universal_cmbd_foundation 2019.11 Yes
Application hp universal_cmbd_foundation 2020.05. Yes
Application microfocus application_performance_management 9.40 Yes
Application microfocus application_performance_management 9.50 Yes
Application microfocus application_performance_management 9.51 Yes
Application microfocus data_center_automation ≤ 2019.11 Yes
Application microfocus hybrid_cloud_management ≤ 2020.05 Yes
Application microfocus service_manager_automation 2020.02 Yes
Application microfocus service_manager_automation 2020.05 Yes

References