CVE-2020-11854
published 2020-10-27CVE-2020-11854: Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in…
PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
74.23%
99.4th percentile
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| micro_focus | application_performance_management | — | — |
| micro_focus | application_performance_management | — | — |
| micro_focus | application_performance_management | — | — |
| micro_focus | operation_bridge | — | — |
| micro_focus | operation_bridge | — | — |
| micro_focus | operation_bridge | — | — |
| micro_focus | operation_bridge | — | — |
| micro_focus | operation_bridge | — | — |
| micro_focus | operation_bridge | — | — |
| micro_focus | operation_bridge | — | — |
| micro_focus | operation_bridge | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | — | — |
| micro_focus | operation_bridge_manager | unspecified – 10.10 | — |
| microfocus | application_performance_management | — | — |
| microfocus | application_performance_management | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring POST requests to /ucmdb-ui/cms/loginRequest.do with username=diagnostics and password matching base64-encoded 'admin', indicating use of the hardcoded credential. ↗
- →Detect vulnerable UCMDB instances by checking GET /ucmdb-api/connect for response body containing both 'HttpUcmdbServiceProviderFactoryImpl' and 'ServerVersion=11.6.0' with HTTP 200. ↗
- →Presence of LWSSO_COOKIE_KEY in response headers after login to /ucmdb-ui/cms/loginRequest.do indicates successful authentication with default diagnostics credentials, a precursor to RCE chaining. ↗
- →The exploit chains hardcoded credential abuse (CVE-2020-11854) with Java deserialization via ysoserial CommonsBeanutils1; monitor for large serialized Java object payloads sent to UCMDB HTTP endpoints post-authentication. ↗
- ·The hardcoded credential (diagnostics/admin) is the root enabler of unauthenticated RCE; this is a static credential baked into the product, not a user-configurable value. ↗
- ·The Nuclei template fingerprints specifically ServerVersion=11.6.0 in the /ucmdb-api/connect response; detections scoped to this version string may miss other vulnerable versions. ↗
- ·The Metasploit module notes the exploit 'can probably also be used' against Operations Bridge Manager (containerized) and APM, but primary testing was against OBM 2020.05 and below. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g58f-4539-9qhg: Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerabil
ghsa_unreviewed·2022-05-24
CVE-2020-11854 [CRITICAL] CWE-287 GHSA-g58f-4539-9qhg: Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerabil
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.
VulnCheck
Micro Focus application_performance_management Use of Hard-coded Credentials
vulncheck·2020·CVSS 9.8
CVE-2020-11854 [CRITICAL] Micro Focus application_performance_management Use of Hard-coded Credentials
Micro Focus application_performance_management Use of Hard-coded Credentials
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code exe
No detection rules found.
Metasploit
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
metasploit
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
This module exploits two vulnerabilities, that when chained allow an attacker to achieve unauthenticated remote code execution in Micro Focus UCMDB. UCMDB included in versions 2020.05 and below of Operations Bridge Manager are affected, but this module can probably also be used to exploit Operations Bridge Manager (containerized) and Application Performance Management. Check the advisory and module documentation for details. The first vulnerability is a hardcoded password for the "diagnostics" user, which allows us to login to UCMDB. The second vulnerability is a run-of-the-mill Java deserialization, which can be exploited with ysoserial's CommonsBeanutils1 payload. Both Windows and Linux installations are vulner
Nuclei
Micro Focus Checks
nuclei·CVSS 8.8
CVE-2020-11853 [HIGH] Micro Focus Checks
Micro Focus Checks
A simple workflow that runs all Micro Focus related nuclei templates on a given target.
Template:
id: micro-focus-workflow
info:
name: Micro Focus Checks
author: dwisiswant0
description: A simple workflow that runs all Micro Focus related nuclei templates on a given target.
workflows:
- template: http/default-logins/UCMDB/
- template: http/cves/2020/CVE-2020-11853.yaml
- template: http/cves/2020/CVE-2020-11854.yaml
Nuclei
Micro Focus Universal CMDB Default Login
nuclei·CVSS 8.8
CVE-2020-11853 [HIGH] Micro Focus Universal CMDB Default Login
Micro Focus Universal CMDB Default Login
Micro Focus Universal CMDB default login credentials were discovered for diagnostics/admin. Note there is potential for this to be chained together with other vulnerabilities as with CVE-2020-11853 and CVE-2020-11854.
Template:
id: ucmdb-default-login
info:
name: Micro Focus Universal CMDB Default Login
author: dwisiswant0
severity: high
description: Micro Focus Universal CMDB default login credentials were discovered for diagnostics/admin. Note there is potential for this to be chained together with other vulnerabilities as with CVE-2020-11853 and CVE-2020-11854.
reference:
- https://packetstormsecurity.com/files/161182/Micro-Focus-UCMDB-Remote-Code-Execution.htm
classification:
cwe-id: CWE-798
metadata:
max-request: 1
tags: ucmdb,default-login
Nuclei
Micro Focus UCMDB - Remote Code Execution
nuclei·CVSS 9.8
CVE-2020-11854 [CRITICAL] Micro Focus UCMDB - Remote Code Execution
Micro Focus UCMDB - Remote Code Execution
Micro Focus UCMDB is susceptible to remote code execution. Impacted products include Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions, and Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.), and Application Performance Management versions 9,51, 9.50 and 9.40 with UCMDB 10.33 CUP 3.
Template:
id: CVE-2020-11854
info:
name: Micro Focus UCMDB - Remote Code Execution
author: dwisiswant0
severity: critical
description: |
Micro Focus UCMDB is susceptible to remote code execution. Impacted products include Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,
No writeups or analysis indexed.
http://packetstormsecurity.com/files/161182/Micro-Focus-UCMDB-Remote-Code-Execution.htmlhttps://softwaresupport.softwaregrp.com/doc/KM03747657https://softwaresupport.softwaregrp.com/doc/KM03747658https://softwaresupport.softwaregrp.com/doc/KM03747854https://www.zerodayinitiative.com/advisories/ZDI-20-1287/http://packetstormsecurity.com/files/161182/Micro-Focus-UCMDB-Remote-Code-Execution.htmlhttps://softwaresupport.softwaregrp.com/doc/KM03747657https://softwaresupport.softwaregrp.com/doc/KM03747658https://softwaresupport.softwaregrp.com/doc/KM03747854https://www.zerodayinitiative.com/advisories/ZDI-20-1287/
2020-10-27
Published
Exploited in the wild