← Vulnerability feed

Vulnerability record · CVE-2021-22506 · published 26 March 2021

CVE-2021-22506: Micro Focus Access Manager information leakage via exposed configuration

Microfocus · Access Manager

Micro Focus Access Manager versions prior to 5.0 expose an information leakage flaw through an advanced configuration path. The record does not specify which data is leaked or the exact mechanism, only that the issue affects all versions before 5.0. It matters because the endpoint is network-reachable without credentials, and the vendor's fix is a version upgrade rather than a configuration toggle.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 26% · top 2.1%
7.5CVSS 3.1 base score, v2 5.0
26%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated information disclosure with confirmed KEV listing and high EPSS, though the leaked data type is unspecified.

What it is

Micro Focus Access Manager versions prior to 5.0 expose an information leakage flaw through an advanced configuration path. The record does not specify which data is leaked or the exact mechanism, only that the issue affects all versions before 5.0. It matters because the endpoint is network-reachable without credentials, and the vendor's fix is a version upgrade rather than a configuration toggle.

Impact

An unauthenticated remote attacker can read information the product was not intended to expose. The record does not state whether that data includes credentials, session tokens or internal configuration, so the practical value to an attacker cannot be confirmed from this record alone.

Attack surface

Reachable over the network via the affected configuration functionality, per the CVSS vector AV:N/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not name the specific endpoint or parameter, so defenders must rely on the vendor release notes to locate it.

Exploitation

Listed in CISA KEV with a due date of 2021-11-17, indicating exploitation in the wild at the time of addition; EPSS 30-day probability is about 0.257 (97.9th percentile). No ransomware campaign use is recorded, and the references are release notes and the KEV entry only, with no public exploit or PoC tag.

What to do

  • Upgrade Access Manager to version 5.0 or later, which the vendor release notes identify as the fixed release.
  • If immediate upgrade is not possible, restrict network access to the Access Manager administrative and advanced configuration interfaces to trusted management networks.
  • Review Access Manager logs and configuration for unexpected reads of advanced configuration data and rotate any secrets that may have been exposed.
  • Confirm the deployed version against the vendor release notes, since all versions prior to 5.0 are stated as affected.

Detection

  • Monitor HTTP requests to Access Manager advanced configuration endpoints for unusual source IPs or user agents, especially unauthenticated requests.
  • Alert on anomalous response sizes or repeated requests to configuration paths that normally return small or empty bodies.
  • Correlate Access Manager access logs with outbound traffic from the server to detect data exfiltration following configuration reads.
  • Track version inventory to flag any Access Manager instance still below 5.0.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22506 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Micro Focus Access Manager Information Leakage Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22506 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-11878Microfocus access manager cross-site scripting vulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scrip…EPSS 0.22%7.5CVE-2021-22527Microfocus access manager information exposure vulnerabilityInformation leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4EPSS 0.73%7.5CVE-2021-22496Microfocus access manager improper authentication vulnerabilityAuthentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could caus…EPSS 1.1%6.8CVE-2014-5217Microfocus access manager cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4…EPSS 1.4%6.3CVE-2026-11877Microfocus access manager vulnerabilityAn unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.…EPSS 0.31%6.1CVE-2021-22531Microfocus access manager cross-site scripting vulnerabilityA bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affe…EPSS 0.56%6.1CVE-2021-22526Microfocus access manager open redirect vulnerabilityOpen Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4EPSS 0.49%6.1CVE-2020-25840Microfocus access manager cross-site scripting vulnerabilityCross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause con…EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2021-22506), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.