CVE-2020-11856: Micro Focus Operations Bridge Reporter JMX Missing Authentication Remote Code Execution Vulnerability
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the JMX remote interface. This interface allows a remote attacker to register attacker-controlled MBeans. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11856.
What is the severity of CVE-2020-11856?
The severity of CVE-2020-11856 is critical with a score of 9.8.
How does the vulnerability CVE-2020-11856 allow remote code execution?
The vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter by exploiting the misconfiguration of the JMX remote interface.
Is authentication required to exploit CVE-2020-11856?
No, authentication is not required to exploit this vulnerability.
How can I fix CVE-2020-11856?
To fix CVE-2020-11856, it is recommended to apply the necessary patches or updates provided by Micro Focus.