CVE-2020-11853: Arbitrary code execution vulnerability on multiple Micro Focus products
Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11853?
CVE-2020-11853 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2020-11853?
To remediate CVE-2020-11853, users should update their systems to the latest patched versions of the affected Micro Focus products.
What products are affected by CVE-2020-11853?
CVE-2020-11853 affects several Micro Focus products including Operation Bridge Manager and Application Performance Management across multiple versions.
What are the potential impacts of CVE-2020-11853?
Exploitation of CVE-2020-11853 could allow an attacker to execute arbitrary code on the affected systems.
Are there any workarounds for CVE-2020-11853?
While the best approach is to apply patches, temporarily limiting access to affected systems may serve as a workaround for CVE-2020-11853.