← Vulnerability feed

Vulnerability record · CVE-2020-11853 · published 22 October 2020

CVE-2020-11853: Micro Focus enterprise products remote code execution flaw

Microfocus · Operation Bridge Manager

CVE-2020-11853 is an arbitrary code execution vulnerability affecting a broad set of Micro Focus products, including Operations Bridge Manager, Universal CMDB, Application Performance Management, Data Center Automation, Hybrid Cloud Management and Service Management Automation. The record does not identify the specific root cause, but the flaw allows code execution on affected systems, which matters because these are management and monitoring platforms often holding privileged access to the rest of the environment.

8.8 CVSS 3.1 High EPSS 77% · top 0.5%
8.8CVSS 3.1 base score, v2 6.5
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability and full code execution impact, plus very high EPSS and public exploit write-ups, though it requires an authenticated low-privileged account and is not in KEV.

What it is

CVE-2020-11853 is an arbitrary code execution vulnerability affecting a broad set of Micro Focus products, including Operations Bridge Manager, Universal CMDB, Application Performance Management, Data Center Automation, Hybrid Cloud Management and Service Management Automation. The record does not identify the specific root cause, but the flaw allows code execution on affected systems, which matters because these are management and monitoring platforms often holding privileged access to the rest of the environment.

Impact

An attacker with a valid low-privileged account can execute arbitrary code on the affected server, gaining full control of confidentiality, integrity and availability of that host. From there, the attacker can pivot into managed infrastructure and data the product administers.

Attack surface

The vulnerability is reachable over the network with no user interaction, but it requires a low-privileged authenticated account per the CVSS vector (AV:N/AC:L/PR:L/UI:N). No pre-authentication path is described in the record.

Exploitation

The CVE is not listed in CISA KEV, but EPSS is very high at roughly 0.77 (99.5th percentile), and public Packet Storm exploit write-ups exist for UCMDB and Operations Bridge Manager, indicating public exploit material is available. No ransomware use is documented.

What to do

  • Apply the vendor patches referenced in the Micro Focus security bulletins (KM03747657, KM03747658, KM03747854, KM03747948, KM03747949, KM03747950, KM03749879) for every affected product and version.
  • Upgrade or remove end-of-life versions (10.1x, 10.6x, 11, 2017.x, 2018.x) that may no longer receive fixes.
  • Restrict network access to the affected management interfaces and place them behind authenticated reverse proxies or VPN-only segments.
  • Enforce least privilege and review accounts with access to these products, since exploitation requires only a low-privileged authenticated user.
  • Monitor vendor advisories for updated guidance, as the record does not describe the underlying flaw.

Detection

  • Hunt for unexpected child processes spawned by Micro Focus product service accounts (for example web/app server processes launching cmd.exe, powershell or /bin/sh).
  • Review authentication logs for anomalous or newly created low-privileged accounts accessing UCMDB, Operations Bridge Manager or related web endpoints.
  • Monitor for outbound connections from management servers to unusual internal hosts or the internet, which may indicate post-exploitation pivoting.
  • Alert on access to the known exploit paths referenced in the public Packet Storm write-ups for UCMDB and Operations Bridge Manager.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11853 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-22514Microfocus application performance management vulnerabilityAn arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9.40, 9.50 and 9.51. The vulne…EPSS 2.0%9.8CVE-2020-11854Micro Focus Operations Bridge and APM hard-coded credentials allow remote code executionMicro Focus Operations Bridge Manager, Operations Bridge (containerized) and Application Performance Management contain a hard-coded credentials flaw…EPSS 74%analysed9.8CVE-2018-6498Microfocus data center automation code injection vulnerabilityRemote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con…EPSS 3.1%9.8CVE-2018-6499Microfocus data center automation code injection vulnerabilityRemote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Con…EPSS 2.4%9.8CVE-2016-4368Hp universal cmbd foundation improper input validation vulnerabilityHPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remo…EPSS 4.7%7.5CVE-2016-4367Hp universal cmbd foundation information exposure vulnerabilityThe Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive infor…EPSS 7.5%7.4CVE-2016-2001Hp universal cmbd foundation vulnerabilityHPE Universal CMDB Foundation 10.0, 10.01, 10.10, 10.11, and 10.20 allows remote attackers to obtain sensitive information or conduct URL redirection…EPSS 2.0%6.5CVE-2021-22500Microfocus application performance management cross-site request forgery vulnerabilityCross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulne…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2020-11853), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.