CVE-2021-22502 is a critical Remote Code Execution vulnerability affecting Micro Focus Operation Bridge Reporter (OBR) version 10.40. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code on the OBR server over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as indicated by its presence in the CISA KEV catalog and the availability of Metasploit modules and Nuclei templates. The high EPSS score and significant community discussion further underscore its widespread attention and exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.40CPE matchmatch criteria | cpe:2.3:a:microfocus:operation_bridge_reporter:10.40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.