Unknown
CVE-2020-11854
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-11854
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- microfocus
Products
- application performance management 9.40,
- application performance management 9.50,
- application performance management 9.51,
- operations bridge 2017.11,
- operations bridge 2018.02,
- operations bridge 2018.05,
- operations bridge 2018.08,
- operations bridge 2018.11,
- operations bridge 2019.05,
- operations bridge 2019.08,
- operations bridge 2020.05,
- operations bridge manager,
- operations bridge manager 10.11,
- operations bridge manager 10.12,
- operations bridge manager 10.60,
- operations bridge manager 10.61,
- operations bridge manager 10.62,
- operations bridge manager 10.63,
- operations bridge manager 2018.05,
- operations bridge manager 2018.11,
- operations bridge manager 2019.05,
- operations bridge manager 2019.11,
- operations bridge manager 2020.05
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: