First published: Tue Sep 22 2020(Updated: )
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.
Credit: security@microfocus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Operation Bridge Reporter | <=10.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-11856.
The severity of CVE-2020-11856 is critical with a score of 9.8.
The vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter by exploiting the misconfiguration of the JMX remote interface.
No, authentication is not required to exploit this vulnerability.
To fix CVE-2020-11856, it is recommended to apply the necessary patches or updates provided by Micro Focus.