CVE-2020-11854
CRITICAL EXPLOITED IN THE WILD NUCLEIMicrofocus Application Performance Management - Hard-coded Credentials
Title source: ruleDescription
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.
Nuclei Templates (1)
Micro Focus UCMDB - Remote Code Execution
CRITICALby dwisiswant0
References (5)
Scores
CVSS v3
9.8
EPSS
0.9240
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-01-13
InTheWild.io
2024-05-17
CWE
CWE-798
Status
published
Products (23)
microfocus/application_performance_management
9.50
microfocus/application_performance_management
9.51
microfocus/application_performance_management
9.40
microfocus/operations_bridge
2017.11
microfocus/operations_bridge
2018.02
microfocus/operations_bridge
2018.05
microfocus/operations_bridge
2018.08
microfocus/operations_bridge
2018.11
microfocus/operations_bridge
2019.05
microfocus/operations_bridge
2019.08
... and 13 more
Published
Oct 27, 2020
Tracked Since
Feb 18, 2026