CVE-2020-11858 is a local privilege escalation vulnerability affecting multiple versions of Micro Focus Operation Bridge Manager and Operation Bridge (containerized). A local attacker can exploit this flaw to execute arbitrary code with escalated privileges on the affected systems. With a CVSS score of 7.8 (HIGH), the vulnerability has a low attack complexity and no user interaction required, leading to high impacts on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog or showing significant community discussion, a Metasploit module exists, indicating public exploit code availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2017.11CPE matchmatch criteria | cpe:2.3:a:microfocus:operations_bridge:2017.11:*:*:*:*:*:*:* | ||
2018.02CPE matchmatch criteria | cpe:2.3:a:microfocus:operations_bridge:2018.02:*:*:*:*:*:*:* | ||
2018.05CPE matchmatch criteria | cpe:2.3:a:microfocus:operations_bridge:2018.05:*:*:*:*:*:*:* | ||
2018.08CPE matchmatch criteria | cpe:2.3:a:microfocus:operations_bridge:2018.08:*:*:*:*:*:*:* | ||
2018.11CPE matchmatch criteria | cpe:2.3:a:microfocus:operations_bridge:2018.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.