EXPOSURES › CVE-2021-22502
CVE-2021-22502
HIGH ⌖ ON CISA KEV · EXPLOITEDMicro Focus Operation Bridge Report (OBR) suffered a remote code execution vulnerability that was actively exploited in the wild.
Micro Focus Operation Bridge Report (OBR) contained an unspecified vulnerability allowing remote code execution, which was listed in CISA's KEV catalog as actively exploited. DIB organizations must ensure their monitoring and reporting tools are patched and monitored for exploitation, as unpatched RCE flaws in critical infrastructure software can lead to full system compromise and data exfiltration.
Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating negligent patching and avoidable compromise of a critical monitoring tool.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.
"Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution."
"CISA Known Exploited Vulnerabilities (KEV)"