CVE-2020-11853

HIGHCVSS 8.8/10EPSS 76.99%

Last modified

CVE-2020-11853 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. EPSS estimates a 76.99% chance of exploitation in the next 30 days.

Description

Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
76.99%

99.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
MicrofocusOperation Bridge Manager<= 10.10
MicrofocusOperation Bridge Manager10.11
MicrofocusOperation Bridge Manager10.12
MicrofocusOperation Bridge Manager10.60
MicrofocusOperation Bridge Manager10.61
MicrofocusOperation Bridge Manager10.62
MicrofocusOperation Bridge Manager10.63
MicrofocusOperations Bridge Manager2017.11
MicrofocusOperations Bridge Manager2018.02
MicrofocusOperations Bridge Manager2018.05
MicrofocusOperations Bridge Manager2018.08
MicrofocusOperations Bridge Manager2018.11
MicrofocusOperations Bridge Manager2019.05
MicrofocusOperations Bridge Manager2019.08
MicrofocusOperations Bridge Manager2019.11
MicrofocusOperations Bridge Manager2020.05
HpUniversal Cmbd Foundation10.20
HpUniversal Cmbd Foundation10.30
HpUniversal Cmbd Foundation10.31
HpUniversal Cmbd Foundation10.32
HpUniversal Cmbd Foundation10.33
HpUniversal Cmbd Foundation11.0
HpUniversal Cmbd Foundation2018.05
HpUniversal Cmbd Foundation2018.08
HpUniversal Cmbd Foundation2018.11
HpUniversal Cmbd Foundation2019.02
HpUniversal Cmbd Foundation2019.05
HpUniversal Cmbd Foundation2019.11
HpUniversal Cmbd Foundation2020.05.
MicrofocusApplication Performance Management9.40
MicrofocusApplication Performance Management9.50
MicrofocusApplication Performance Management9.51
MicrofocusData Center Automation<= 2019.11
MicrofocusHybrid Cloud Management>= 2018.05, <= 2020.05
MicrofocusService Manager Automation2020.02
MicrofocusService Manager Automation2020.05

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-11853?
Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.
How severe is CVE-2020-11853?
CVE-2020-11853 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 76.99% probability of exploitation in the next 30 days.
How do I fix CVE-2020-11853?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-11853?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST