LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22502: Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22502 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.

CVE-2021-22502 is a remote code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR). An attacker who can reach a vulnerable instance may be able to run code on the underlying system. For IT and security teams that rely on OBR for operations reporting, this matters because successful exploitation can give an outsider a foothold inside the management plane, with access to the host and potentially to connected infrastructure data.

Public detail on the exact trigger is limited. CISA describes an unspecified flaw that allows remote code execution; the associated weakness classes are improper input validation (CWE-20) and OS command injection (CWE-78). Confirm affected releases, fixed builds, and deployment notes directly against the vendor advisory before acting.

How it works

At a high level, the issue combines weak input handling with the ability to influence operating-system commands. Products in this class often accept parameters from authenticated or network-reachable interfaces—reports, queries, administrative functions, or integration endpoints—and pass some of that data into shell or system calls. When input is not strictly validated or sanitized, an attacker can craft values that break out of the intended command and execute arbitrary instructions with the privileges of the OBR process.

Abuse typically requires network reachability to the vulnerable service. Depending on how OBR is deployed and exposed, that may mean an unauthenticated remote attacker or an attacker who already has some level of access. The result is code execution on the host running OBR, which can lead to persistence, lateral movement, or theft of reporting and configuration data. Specific request formats, parameters, or preconditions are not detailed in the public summary; treat any internet-facing or broadly reachable OBR instance as higher risk until patched and verified.

Am I affected? How to find it in your systems

Operation Bridge Reporter is typically deployed in enterprise operations and IT management environments—often on dedicated servers or VMs that collect and present performance and availability data. It may sit alongside other Micro Focus / OpenText operations tools and is sometimes reachable from management networks or, less commonly, from broader corporate networks.

If inventory is incomplete, prioritize any host that presents OBR-branded web interfaces or that is documented as an operations reporting node.

How to remediate

Patch first. Apply the updates supplied by the vendor for Operation Bridge Reporter exactly as described in the official advisory. CISA’s required action is to apply updates per vendor instructions; do not rely on third-party version lists alone.

Document the change and retain evidence of the advisory version you applied for audit and incident-response purposes.

If you can't patch immediately

Reduce exposure until the vendor update can be installed.

Revisit the compensating controls as soon as the official update is deployed and validated.

If your data may have been exposed

Actively exploited remote code execution flaws are a common path into breaches. If you have reason to believe an OBR instance was reachable and unpatched during a period of suspected activity, treat the host as potentially compromised: isolate it, preserve logs and disk evidence, rotate credentials and secrets that the service could access, and hunt for persistence and lateral movement. Known ransomware use of this CVE is not documented, but that does not eliminate other post-exploitation risk. As a routine check, you can run a free exposure scan of your email addresses against known breach data to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicro Focus · Operation Bridge Reporter (OBR)
WeaknessCWE-20
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities