Where
-Infinity
0
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

1 / 2
First published (updated )
Severity
9.8
OS Command Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.

1 / 2
Source: CISA
First published (updated )
Severity
7
CSRF

Problem Summary: WebInspect has identified that the application under test using the OAuth2 protocol is using an insufficient entropy in the state parameter value in the workflow. This introduces a CSRF vulnerability in the context of the OAuth process, and gives the ability to login to the victim’s current application account using a third-party account without any restrictions. In authorization code type and implicit grant type, the OAuth protocol is vulnerable to a CSRF attack if the state parameter is used inefficiently. An attacker can perform a normal OAuth2 process and get the redirection URL that contains the authorization code of the third-party. The attacker can bind his account to victim’s account for the vulnerable application by enticing a victim to access this URL. If the state parameter is set in the redirection URL but without sufficient entropy, then an attacker can predict the user’s state parameter and forge reliable a redirection URL to induce the victim to access and implement CSRF attack. In this case WebInspect detetced that the session is using OAuth2 and insert an state parameter in the query variables: 5189522f as CSRF token. However, the WebInspect has found that the value of state parameter maybe guessable to be predicted. The attacker could predict the next token of the user and then get it exploited.

Steps to reproduce:

- Initiate the OAuth2 binding process - Extract the state parameter value in the redirection URL to the authorization server - Repeat the previous steps again and get a new state parameter value - Try to analyze the order between two state parameters and predict the victim’s state parameter value - Finished logging into authorization server - The authorization server attempts to redirect the user to the client application, do not follow the redirection - Modify the state parameter value with a predicted value to which the victim might be assigned. - Send the redirection URL with the predicted state parameter value to the victim who is now in login status of the client application - Note if the victim’s client application account is bound to the attacker’s third-party account.

Implication: The attacker can gain access to other user’s accounts and access sensitive information of the profile, or perform arbitrary actions using the victim’s account.

Suggestions: Improve the entropy of state parameter value.

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.

First published (updated )
Severity
5.8
Input Validation
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open services enumeration. Server makes query to provided server (Server IP/DNS field) and is triggering connection to arbitrary address.

First published (updated )
Severity
6.5
Path Traversal
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).

First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.

1 / 2
First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

1 / 2

Remedy

For Operation Bridge Manager https://softwaresupport.softwaregrp.com/doc/KM03747658 For Operation Bridge (containerized) https://softwaresupport.softwaregrp.com/doc/KM03747854 For Application Performance Management https://softwaresupport.softwaregrp.com/doc/KM03747657
First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Bridge (containerized). The vulneravility affects: 1.) Operation Bridge Manager versions: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) versions: 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. The vulnerability could allow local attackers to execute code with escalated privileges.

1 / 2

Remedy

For Operation Bridge Manager https://softwaresupport.softwaregrp.com/doc/KM03747658 For Operation Bridge (containerized) https://softwaresupport.softwaregrp.com/doc/KM03747854
First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user

1 / 2
First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with escalated privileges.

1 / 2
First published (updated )
EOL
Jul 31, 2028

End of life: 7/31/2028

First published (updated )
EOL
Jul 31, 2028

End of life: 7/31/2028

First published (updated )
EOL
Jul 31, 2027

End of life: 7/31/2027

First published (updated )
EOL
Jul 31, 2027

End of life: 7/31/2027

First published (updated )
EOL
Jul 31, 2026

End of life: 7/31/2026

First published (updated )
EOL
Jul 31, 2026

End of life: 7/31/2026

First published (updated )
EOL
Sep 30, 2025

End of life: 9/30/2025

First published (updated )
EOL
Sep 30, 2025

End of life: 9/30/2025

First published (updated )
EOL
Jun 30, 2024

End of life: 6/30/2024

First published (updated )
EOL
Jun 30, 2024

End of life: 6/30/2024

First published (updated )
EOL
May 31, 2017

End of life: 5/31/2017

First published (updated )
EOL
May 31, 2017

End of life: 5/31/2017

First published (updated )
EOL
Dec 31, 2014

End of life: 12/31/2014

First published (updated )
EOL
Dec 31, 2014

End of life: 12/31/2014

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the JMX remote interface. This interface allows a remote attacker to register attacker-controlled MBeans. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

Advisory
ZDI-20-1216
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the JMX remote interface. This interface allows a remote attacker to register attacker-controlled MBeans. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

Severity
7.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter. Authentication is not required to exploit this vulnerability. The specific flaw exists within the creation of the shrboadmin user during installation. The product contains a hard-coded password for this account. An attacker can leverage this vulnerability to execute arbitrary code in the context of the shrboadmin user.

Advisory
ZDI-20-1215
Severity
7.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Micro Focus Operations Bridge Reporter. Authentication is not required to exploit this vulnerability. The specific flaw exists within the creation of the shrboadmin user during installation. The product contains a hard-coded password for this account. An attacker can leverage this vulnerability to execute arbitrary code in the context of the shrboadmin user.

Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

This vulnerability allows local attackers to escalate privileges on affected installations of Micro Focus Operations Bridge Reporter. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product's installer. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM.

Advisory
ZDI-20-1217

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203