CVE-2020-11854
Summary
| CVE | CVE-2020-11854 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-27 17:15:00 UTC |
| Updated | 2023-11-07 03:15:00 UTC |
| Description | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microfocus | Application Performance Management | 9.40 | All | All | All |
| Application | Microfocus | Application Performance Management | 9.50 | All | All | All |
| Application | Microfocus | Application Performance Management | 9.51 | All | All | All |
| Application | Microfocus | Application Performance Management | 9.40 | All | All | All |
| Application | Microfocus | Application Performance Management | 9.50 | All | All | All |
| Application | Microfocus | Application Performance Management | 9.51 | All | All | All |
| Application | Microfocus | Operations Bridge | 2017.11 | All | All | All |
| Application | Microfocus | Operations Bridge | 2018.02 | All | All | All |
| Application | Microfocus | Operations Bridge | 2018.05 | All | All | All |
| Application | Microfocus | Operations Bridge | 2018.08 | All | All | All |
| Application | Microfocus | Operations Bridge | 2018.11 | All | All | All |
| Application | Microfocus | Operations Bridge | 2019.05 | All | All | All |
| Application | Microfocus | Operations Bridge | 2019.08 | All | All | All |
| Application | Microfocus | Operations Bridge | 2020.05 | All | All | All |
| Application | Microfocus | Operations Bridge | 2017.11 | All | All | All |
| Application | Microfocus | Operations Bridge | 2018.02 | All | All | All |
| Application | Microfocus | Operations Bridge | 2018.05 | All | All | All |
| Application | Microfocus | Operations Bridge | 2018.08 | All | All | All |
| Application | Microfocus | Operations Bridge | 2018.11 | All | All | All |
| Application | Microfocus | Operations Bridge | 2019.05 | All | All | All |
| Application | Microfocus | Operations Bridge | 2019.08 | All | All | All |
| Application | Microfocus | Operations Bridge | 2020.05 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.11 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.12 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.60 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.61 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.62 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.63 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2018.05 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2018.11 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2019.05 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2019.11 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2020.05 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.11 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.12 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.60 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.61 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.62 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 10.63 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2018.05 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2018.11 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2019.05 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2019.11 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | 2020.05 | All | All | All |
| Application | Microfocus | Operations Bridge Manager | All | All | All | All |
| Application | Microfocus | Universal Cmdb | 10.33 | cumulative_update_package_3 | All | All |
| Application | Microfocus | Universal Cmdb | 10.33 | cumulative_update_package_3 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MySupport - Micro Focus Software Support | softwaresupport.softwaregrp.com | ||
| ZDI-20-1287 | Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| MySupport - Micro Focus Software Support | MISC | softwaresupport.softwaregrp.com | Vendor Advisory |
| Micro Focus UCMDB Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| MySupport - Micro Focus Software Support | MISC | softwaresupport.softwaregrp.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Micro Focus would like to thank Pedro Ribeiro from Agile Information Security working with Trend Micro Zero Day Initiative for discovering and reporting the vulnerability
Legacy QID Mappings
- 375321 Micro Focus Operations Bridge Manager Arbitrary Code Execution Vulnerability(KM03747658)