KEVIntel
9.8
CVSS
Critical

CVE-2021-22502

PUBLISHED

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be...

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Micro Focus
Product
Operation Bridge Reporter.
Published
Feb 08, 2021
EPSS
94.0% · 100% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

cisa nuclei_scanner metasploit

Weaknesses (CWE)

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0 High

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2021-11-03 00:00:00 UTC · CISA

Proof of concept available

Recorded 2025-04-28 15:02:08 UTC

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA First 2021-11-03 00:00 UTC
The Shadowserver (via CIRCL) 2026-05-31 00:00 UTC

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

microfocus_obr_cmd_injection

metasploit · Created Unknown

Metasploit module for CVE-2021-22502

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Proof of Concept Exploit Available

  • Detected by Metasploit

  • KEV confirmed by The Shadowserver (via CIRCL)