FAIL › dossier
Micro Focus
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-22506 | high | Micro Focus Access Manager leaked sensitive data via a SAML redirection flaw that was actively exploited in the wild. |
| 2021-11-03 | CVE-2021-22502 | high | Micro Focus Operation Bridge Report (OBR) suffered a remote code execution vulnerability that was actively exploited in the wild. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
Vulnerability confirmed in critical SAML component, indicating significant security oversight.
synthesissevere-fallout-0.80
Vendor failed to disclose vulnerability in OBR, allowing remote code execution to remain hidden until exploited.
Damning disclosure failure
"Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution."
Neutral CVEFeed catalog
"CISA Known Exploited Vulnerabilities (KEV)"
Vulnerability confirmed in critical SAML component, indicating significant security oversight.
"Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used."