Vulnerability record · CVE-2020-11853 · published 22 October 2020
CVE-2020-11853: Micro Focus enterprise products remote code execution flaw
Microfocus · Operation Bridge Manager
CVE-2020-11853 is an arbitrary code execution vulnerability affecting a broad set of Micro Focus products, including Operations Bridge Manager, Universal CMDB, Application Performance Management, Data Center Automation, Hybrid Cloud Management and Service Management Automation. The record does not identify the specific root cause, but the flaw allows code execution on affected systems, which matters because these are management and monitoring platforms often holding privileged access to the rest of the environment.
Description
Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and full code execution impact, plus very high EPSS and public exploit write-ups, though it requires an authenticated low-privileged account and is not in KEV.
What it is
CVE-2020-11853 is an arbitrary code execution vulnerability affecting a broad set of Micro Focus products, including Operations Bridge Manager, Universal CMDB, Application Performance Management, Data Center Automation, Hybrid Cloud Management and Service Management Automation. The record does not identify the specific root cause, but the flaw allows code execution on affected systems, which matters because these are management and monitoring platforms often holding privileged access to the rest of the environment.
Impact
An attacker with a valid low-privileged account can execute arbitrary code on the affected server, gaining full control of confidentiality, integrity and availability of that host. From there, the attacker can pivot into managed infrastructure and data the product administers.
Attack surface
The vulnerability is reachable over the network with no user interaction, but it requires a low-privileged authenticated account per the CVSS vector (AV:N/AC:L/PR:L/UI:N). No pre-authentication path is described in the record.
Exploitation
The CVE is not listed in CISA KEV, but EPSS is very high at roughly 0.77 (99.5th percentile), and public Packet Storm exploit write-ups exist for UCMDB and Operations Bridge Manager, indicating public exploit material is available. No ransomware use is documented.
What to do
- Apply the vendor patches referenced in the Micro Focus security bulletins (KM03747657, KM03747658, KM03747854, KM03747948, KM03747949, KM03747950, KM03749879) for every affected product and version.
- Upgrade or remove end-of-life versions (10.1x, 10.6x, 11, 2017.x, 2018.x) that may no longer receive fixes.
- Restrict network access to the affected management interfaces and place them behind authenticated reverse proxies or VPN-only segments.
- Enforce least privilege and review accounts with access to these products, since exploitation requires only a low-privileged authenticated user.
- Monitor vendor advisories for updated guidance, as the record does not describe the underlying flaw.
Detection
- Hunt for unexpected child processes spawned by Micro Focus product service accounts (for example web/app server processes launching cmd.exe, powershell or /bin/sh).
- Review authentication logs for anomalous or newly created low-privileged accounts accessing UCMDB, Operations Bridge Manager or related web endpoints.
- Monitor for outbound connections from management servers to unusual internal hosts or the internet, which may indicate post-exploitation pivoting.
- Alert on access to the known exploit paths referenced in the public Packet Storm write-ups for UCMDB and Operations Bridge Manager.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-11853 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11853), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.