RULE(RULE ID:333512)

Rule General Information
Release Date: 2021-05-08
Rule Name: Micro Focus Operations Bridge Reporter Unauthenticated Command Injection Vulnerability (CVE-2021-22502)
Severity:
CVE ID:
Rule Protection Details
Description: Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html
https://softwaresupport.softwaregrp.com/doc/KM03775947
ZeroDayInitiative:ZDI-21-153
ZeroDayInitiative:ZDI-21-154
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://softwaresupport.softwaregrp.com/doc/KM03775947