ZDI-20-1216: Micro Focus Operations Bridge Reporter JMX Missing Authentication Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the JMX remote interface. This interface allows a remote attacker to register attacker-controlled MBeans. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-20-1216?
The severity of ZDI-20-1216 is critical due to the possibility of remote code execution without authentication.
How do I fix ZDI-20-1216?
To fix ZDI-20-1216, apply the latest patches and updates provided by Micro Focus for Operations Bridge Reporter.
Who is affected by ZDI-20-1216?
Organizations using vulnerable versions of Micro Focus Operations Bridge Reporter are affected by ZDI-20-1216.
What types of attacks can occur due to ZDI-20-1216?
ZDI-20-1216 allows remote attackers to execute arbitrary code, potentially leading to full system compromise.
Is authentication required to exploit ZDI-20-1216?
No, authentication is not required to exploit ZDI-20-1216.