Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
References
| Link | Resource |
|---|---|
| http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html | Exploit Third Party Advisory VDB Entry |
| https://softwaresupport.softwaregrp.com/doc/KM03775947 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-153/ | Third Party Advisory VDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-21-154/ | Third Party Advisory VDB Entry |
| http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html | Exploit Third Party Advisory VDB Entry |
| https://softwaresupport.softwaregrp.com/doc/KM03775947 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-153/ | Third Party Advisory VDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-21-154/ | Third Party Advisory VDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22502 | US Government Resource |
Configurations
History
27 Oct 2025, 16:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22502 - US Government Resource |
22 Oct 2025, 00:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 05:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry |
25 Jul 2024, 17:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://softwaresupport.softwaregrp.com/doc/KM03775947 - Vendor Advisory | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - Third Party Advisory, VDB Entry | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-21-154/ - Third Party Advisory, VDB Entry |
12 Jul 2022, 17:42
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-78 |
Information
Published : 2021-02-08 22:15
Updated : 2025-10-27 16:58
NVD link : CVE-2021-22502
Mitre link : CVE-2021-22502
CVE.ORG link : CVE-2021-22502
JSON object : View
Products Affected
microfocus
- operation_bridge_reporter
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
