Vulnerability record · CVE-2021-22502 · published 8 February 2021
CVE-2021-22502: Micro Focus Operation Bridge Reporter OS command injection RCE
Microfocus · Operation Bridge Reporter
Micro Focus Operation Bridge Reporter (OBR) version 10.40 contains an OS command injection flaw (CWE-78) that permits remote code execution on the OBR server. It is network-reachable with no privileges or user interaction required, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants urgent remediation.
Description
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network remote code execution with a CVSS of 9.8, KEV listing, and near-maximum EPSS probability.
What it is
Micro Focus Operation Bridge Reporter (OBR) version 10.40 contains an OS command injection flaw (CWE-78) that permits remote code execution on the OBR server. It is network-reachable with no privileges or user interaction required, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants urgent remediation.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the OBR server, gaining full control of that host and its data.
Attack surface
Reachable over the network via the OBR service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed.
Exploitation
Listed in CISA KEV with a 2021-11-17 remediation due date, and EPSS probability is 0.9674 (99.88th percentile); public exploit code is referenced (Packet Storm, ZDI advisories). No ransomware campaign use is documented.
What to do
- Apply the vendor update per Micro Focus advisory KM03775947 (CISA required action).
- If patching cannot be done immediately, isolate OBR servers from untrusted networks and restrict access to trusted management hosts only.
- Audit for OBR 10.40 instances and confirm no unauthorized changes or persistence on the host.
- Monitor and block exploit attempts against the OBR service at network and host boundaries.
Detection
- Inspect OBR server and web logs for command-injection payloads or unexpected shell metacharacters in requests.
- Monitor for unexpected child processes spawned by the OBR service (e.g., shell or command interpreters).
- Alert on outbound connections or file writes from the OBR host that deviate from baseline behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22502 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.htm | ExploitThird Party AdvisoryVDB Entry |
| https://softwaresupport.softwaregrp.com/doc/KM03775947 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-153/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-21-154/ | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.htm | ExploitThird Party AdvisoryVDB Entry |
| https://softwaresupport.softwaregrp.com/doc/KM03775947 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-153/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-21-154/ | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22502 | US Government Resource |
Track CVE-2021-22502 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22502), CISA KEV, FIRST EPSS (scores of 2026-09-21). This page is refreshed as NVD updates the record.