LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22506: Micro Focus Access Manager Information Leakage Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22506 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.

CVE-2021-22506 is an information leakage vulnerability in Micro Focus Access Manager. It stems from a SAML service provider redirection issue when the Assertion Consumer Service URL is used, which can allow unintended disclosure of information. For IT and security teams running this product in identity and access workflows, the issue matters because Access Manager often sits on authentication paths; leakage there can expose details useful for further abuse of federated login flows. Confirm all product and fix details against the vendor advisory.

How it works

Public detail describes this as an information leakage vulnerability caused by a SAML service provider redirection issue tied to use of the Assertion Consumer Service URL. In SAML-based single sign-on, the service provider and identity provider exchange assertions and redirect the user browser to complete authentication. When redirection handling around the Assertion Consumer Service URL is flawed, an attacker who can influence or observe that flow may obtain information that should remain protected.

The exact weakness class (CWE) is not specified in the provided record. At a high level for this product class, the abuse path involves interacting with the SAML redirection behavior so that sensitive data is returned or exposed outside the intended trust boundary. Do not assume specific request parameters, payloads, or preconditions; those must be taken only from the vendor advisory. The practical risk is unauthorized disclosure that can aid reconnaissance or follow-on attacks against the access management environment.

Am I affected? How to find it in your systems

Micro Focus Access Manager is typically deployed as an enterprise identity and access management component, often in front of internal applications, portals, or federated partner integrations that rely on SAML. Inventory any hosts, appliances, or clusters running Access Manager, including development, test, and production instances, and any reverse proxies or load balancers that terminate SAML traffic for it.

If you cannot confirm version or configuration status internally, treat systems running Access Manager SAML SP features as in-scope until verified against the advisory.

How to remediate

Patch first. Apply the updates provided by the vendor for Micro Focus Access Manager exactly as described in the vendor instructions and the CISA-required action to apply updates per vendor instructions. Schedule the change through your normal change process, including backups of configuration and federation metadata, then verify SAML flows still complete correctly after the update.

If the advisory lists additional configuration changes beyond the binary or package update, implement those as part of the same remediation window.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on the SAML redirection and information-leakage class of issues.

These steps do not replace the patch; they only lower likelihood and impact until the vendor fix is installed.

If your data may have been exposed

Actively exploited vulnerabilities in access management products can lead to unauthorized access or data exposure even when ransomware use is not documented for this CVE. If you have indicators of exploitation or cannot rule out exposure, follow your incident response process: preserve logs, rotate relevant secrets and federation credentials as appropriate, and assess what information may have left the system. You can run a free exposure scan of your email addresses to check whether they appear in known breach data and prioritize further monitoring and credential hygiene accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicro Focus · Micro Focus Access Manager
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities