This vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the JMX remote interface. This interface allows a remote attacker to register attacker-controlled MBeans. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA Reports for Operations |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-20-1216 is critical due to the possibility of remote code execution without authentication.
To fix ZDI-20-1216, apply the latest patches and updates provided by Micro Focus for Operations Bridge Reporter.
Organizations using vulnerable versions of Micro Focus Operations Bridge Reporter are affected by ZDI-20-1216.
ZDI-20-1216 allows remote attackers to execute arbitrary code, potentially leading to full system compromise.
No, authentication is not required to exploit ZDI-20-1216.