Vulnerability record · CVE-2021-22506 · published 26 March 2021
CVE-2021-22506: Micro Focus Access Manager information leakage via exposed configuration
Microfocus · Access Manager
Micro Focus Access Manager versions prior to 5.0 expose an information leakage flaw through an advanced configuration path. The record does not specify which data is leaked or the exact mechanism, only that the issue affects all versions before 5.0. It matters because the endpoint is network-reachable without credentials, and the vendor's fix is a version upgrade rather than a configuration toggle.
Description
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityNetwork-reachable, unauthenticated information disclosure with confirmed KEV listing and high EPSS, though the leaked data type is unspecified.
What it is
Micro Focus Access Manager versions prior to 5.0 expose an information leakage flaw through an advanced configuration path. The record does not specify which data is leaked or the exact mechanism, only that the issue affects all versions before 5.0. It matters because the endpoint is network-reachable without credentials, and the vendor's fix is a version upgrade rather than a configuration toggle.
Impact
An unauthenticated remote attacker can read information the product was not intended to expose. The record does not state whether that data includes credentials, session tokens or internal configuration, so the practical value to an attacker cannot be confirmed from this record alone.
Attack surface
Reachable over the network via the affected configuration functionality, per the CVSS vector AV:N/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not name the specific endpoint or parameter, so defenders must rely on the vendor release notes to locate it.
Exploitation
Listed in CISA KEV with a due date of 2021-11-17, indicating exploitation in the wild at the time of addition; EPSS 30-day probability is about 0.257 (97.9th percentile). No ransomware campaign use is recorded, and the references are release notes and the KEV entry only, with no public exploit or PoC tag.
What to do
- Upgrade Access Manager to version 5.0 or later, which the vendor release notes identify as the fixed release.
- If immediate upgrade is not possible, restrict network access to the Access Manager administrative and advanced configuration interfaces to trusted management networks.
- Review Access Manager logs and configuration for unexpected reads of advanced configuration data and rotate any secrets that may have been exposed.
- Confirm the deployed version against the vendor release notes, since all versions prior to 5.0 are stated as affected.
Detection
- Monitor HTTP requests to Access Manager advanced configuration endpoints for unusual source IPs or user agents, especially unauthenticated requests.
- Alert on anomalous response sizes or repeated requests to configuration paths that normally return small or empty bodies.
- Correlate Access Manager access logs with outbound traffic from the server to detect data exfiltration following configuration reads.
- Track version inventory to flag any Access Manager instance still below 5.0.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22506 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Micro Focus Access Manager Information Leakage Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-22506 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22506), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.