CVE-2020-11853 is an arbitrary code execution vulnerability impacting numerous Micro Focus products, including Operation Bridge Manager, Application Performance Management, and Universal CMDB, across many versions. With a CVSS score of 8.8 (High), it allows authenticated attackers to execute arbitrary code remotely over the network with low complexity, leading to high impacts on confidentiality, integrity, and availability. The high EPSS score of 0.92681 and a FAUCET Risk Score of 100/100 indicate a significant likelihood of exploitation. While not in CISA's KEV catalog and lacking public media coverage or community discussion, multiple Metasploit modules and Nuclei templates exist, confirming readily available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.10CPE matchmatch criteria | cpe:2.3:a:microfocus:operation_bridge_manager:*:*:*:*:*:*:*:* | ||
10.11CPE matchmatch criteria | cpe:2.3:a:microfocus:operation_bridge_manager:10.11:*:*:*:*:*:*:* | ||
10.12CPE matchmatch criteria | cpe:2.3:a:microfocus:operation_bridge_manager:10.12:*:*:*:*:*:*:* | ||
10.60CPE matchmatch criteria | cpe:2.3:a:microfocus:operation_bridge_manager:10.60:*:*:*:*:*:*:* | ||
10.61CPE matchmatch criteria | cpe:2.3:a:microfocus:operation_bridge_manager:10.61:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.