CRITICAL

CVE-2020-11854

CVSS v3

9.8

CRITICAL

EPSS Score

92.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

Technical details

Published
10/27/2020

Frequently asked questions

What is CVE-2020-11854?

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

Is CVE-2020-11854 actively exploited?

Active exploitation of CVE-2020-11854 has not been confirmed. The EPSS score is 92.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-11854?

CVE-2020-11854 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-11854 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.