Skip to content
COOEY

EXPOSURES › CVE-2021-22502

CVE-2021-22502

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22502 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Micro Focus Operation Bridge Report (OBR) suffered a remote code execution vulnerability that was actively exploited in the wild.

Micro Focus Operation Bridge Report (OBR) contained an unspecified vulnerability allowing remote code execution, which was listed in CISA's KEV catalog as actively exploited. DIB organizations must ensure their monitoring and reporting tools are patched and monitored for exploitation, as unpatched RCE flaws in critical infrastructure software can lead to full system compromise and data exfiltration.

Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating negligent patching and avoidable compromise of a critical monitoring tool.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Vendor failed to disclose vulnerability in OBR, allowing remote code execution to remain hidden until exploited.
cooey ↗ severe-fallout -0.90
Damning disclosure failure
"Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution."
cvedb.shodan.io ↗ severe-fallout +0.00
Neutral API listing
"CVEDB API - Fast Vulnerability Lookups"
support.apple.com ↗ severe-fallout +0.00
Neutral Apple support page
"Apple security releases"
CISA ↗ severe-fallout +0.00
Neutral CISA advisory page
"ICS Advisories"
cvefeed.io ↗ severe-fallout +0.00
Neutral CVEFeed catalog
"CISA Known Exploited Vulnerabilities (KEV)"
securityonline.info ↗ severe-fallout +0.00
Neutral CVE Watchtower
"CVE Watchtower"
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
"CVE 2026"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.