{"cve":{"cve_id":"CVE-2020-11853","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.7699,"epss_percentile":0.99488,"epss_as_of":"2026-06-23","description":"Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.","published_at":"2020-10-22T20:37:51Z","last_modified_at":null,"cvss_v3_score":8.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_v3_severity":"HIGH","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":null,"nvd_references":["https://softwaresupport.softwaregrp.com/doc/KM03747658","https://softwaresupport.softwaregrp.com/doc/KM03747657","https://softwaresupport.softwaregrp.com/doc/KM03747854","https://softwaresupport.softwaregrp.com/doc/KM03749879","https://softwaresupport.softwaregrp.com/doc/KM03747949","https://softwaresupport.softwaregrp.com/doc/KM03747948","https://softwaresupport.softwaregrp.com/doc/KM03747950","http://packetstormsecurity.com/files/161182/Micro-Focus-UCMDB-Remote-Code-Execution.html","http://packetstormsecurity.com/files/161366/Micro-Focus-Operations-Bridge-Manager-Remote-Code-Execution.html"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:13:20.710940Z"},"effective_severity":"HIGH","badges":["poc","epss"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"L","value_label":"Low"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"application-performance-management","product_name":"Application Performance Management","version_start":"9.50","version_start_inclusive":true,"version_end":"9.50","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:application-performance-management:9.50:9.50"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"application-performance-management","product_name":"Application Performance Management","version_start":"9.40","version_start_inclusive":true,"version_end":"9.40","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:application-performance-management:9.40:9.40"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"application-performance-management","product_name":"Application Performance Management","version_start":"9.51","version_start_inclusive":true,"version_end":"9.51","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:application-performance-management:9.51:9.51"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"data-center-automation","product_name":"Data Center Automation","version_start":"2019.11","version_start_inclusive":true,"version_end":"2019.11","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:data-center-automation:2019.11:2019.11"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"hybrid-cloud-management","product_name":"Hybrid Cloud Management","version_start":"2018.05","version_start_inclusive":true,"version_end":"2020.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:hybrid-cloud-management:2018.05:2020.05"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operation-bridge-manager","product_name":"Operation Bridge Manager","version_start":"2019.05","version_start_inclusive":true,"version_end":"2019.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operation-bridge-manager:2019.05:2019.05"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operation-bridge-manager","product_name":"Operation Bridge Manager","version_start":"2019.11","version_start_inclusive":true,"version_end":"2019.11","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operation-bridge-manager:2019.11:2019.11"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operation-bridge-manager","product_name":"Operation Bridge Manager","version_start":"2018.11","version_start_inclusive":true,"version_end":"2018.11","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operation-bridge-manager:2018.11:2018.11"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operation-bridge-manager","product_name":"Operation Bridge Manager","version_start":"2018.05","version_start_inclusive":true,"version_end":"2018.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operation-bridge-manager:2018.05:2018.05"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operation-bridge-manager","product_name":"Operation Bridge Manager","version_start":"unspecified","version_start_inclusive":true,"version_end":"10.63","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operation-bridge-manager:unspecified:10.63"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operation-bridge-manager","product_name":"Operation Bridge Manager","version_start":"2020.5","version_start_inclusive":true,"version_end":"2020.5","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operation-bridge-manager:2020.5:2020.5"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operations-bridge-containerized","product_name":"Operations Bridge (containerized)","version_start":"2018.02","version_start_inclusive":true,"version_end":"2018.02","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operations-bridge-containerized:2018.02:2018.02"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operations-bridge-containerized","product_name":"Operations Bridge (containerized)","version_start":"2019.11","version_start_inclusive":true,"version_end":"2019.11","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operations-bridge-containerized:2019.11:2019.11"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operations-bridge-containerized","product_name":"Operations Bridge (containerized)","version_start":"2019.08","version_start_inclusive":true,"version_end":"2019.08","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operations-bridge-containerized:2019.08:2019.08"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operations-bridge-containerized","product_name":"Operations Bridge (containerized)","version_start":"2019.05","version_start_inclusive":true,"version_end":"2019.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operations-bridge-containerized:2019.05:2019.05"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operations-bridge-containerized","product_name":"Operations Bridge (containerized)","version_start":"2018.11","version_start_inclusive":true,"version_end":"2018.11","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operations-bridge-containerized:2018.11:2018.11"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operations-bridge-containerized","product_name":"Operations Bridge (containerized)","version_start":"2018.08","version_start_inclusive":true,"version_end":"2018.08","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operations-bridge-containerized:2018.08:2018.08"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operations-bridge-containerized","product_name":"Operations Bridge (containerized)","version_start":"2018.05","version_start_inclusive":true,"version_end":"2018.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operations-bridge-containerized:2018.05:2018.05"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"operations-bridge-containerized","product_name":"Operations Bridge (containerized)","version_start":"2017.11","version_start_inclusive":true,"version_end":"2017.11","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:operations-bridge-containerized:2017.11:2017.11"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"service-management-automation","product_name":"Service Management Automation","version_start":"2020.05","version_start_inclusive":true,"version_end":"2020.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:service-management-automation:2020.05:2020.05"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"service-management-automation","product_name":"Service Management Automation","version_start":"2020.02","version_start_inclusive":true,"version_end":"2020.02","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:service-management-automation:2020.02:2020.02"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"2019.02","version_start_inclusive":true,"version_end":"2019.02","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:2019.02:2019.02"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"2018.11","version_start_inclusive":true,"version_end":"2018.11","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:2018.11:2018.11"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"2018.08","version_start_inclusive":true,"version_end":"2018.08","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:2018.08:2018.08"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"2018.05","version_start_inclusive":true,"version_end":"2018.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:2018.05:2018.05"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"11.0","version_start_inclusive":true,"version_end":"11.0","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:11.0:11.0"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"2019.11","version_start_inclusive":true,"version_end":"2019.11","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:2019.11:2019.11"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"10.32","version_start_inclusive":true,"version_end":"10.32","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:10.32:10.32"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"10.31","version_start_inclusive":true,"version_end":"10.31","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:10.31:10.31"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"10.30","version_start_inclusive":true,"version_end":"10.30","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:10.30:10.30"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"2020.05","version_start_inclusive":true,"version_end":"2020.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:2020.05:2020.05"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"10.33","version_start_inclusive":true,"version_end":"10.33","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:10.33:10.33"},{"vendor_slug":"micro-focus","vendor_name":"Micro Focus","product_slug":"universal-cmdb","product_name":"Universal CMDB","version_start":"2019.05","version_start_inclusive":true,"version_end":"2019.05","version_end_inclusive":true,"cpe23_uri":"cve5:micro-focus:universal-cmdb:2019.05:2019.05"}],"exploit_refs":[{"source":"nuclei","kind":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/workflows/micro-focus-workflow.yaml","title":"Micro Focus Checks","author":"dwisiswant0","disclosed_at":null},{"source":"nuclei","kind":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/default-logins/UCMDB/ucmdb-default-login.yaml","title":"Micro Focus Universal CMDB Default Login","author":"dwisiswant0","disclosed_at":null},{"source":"nuclei","kind":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11853.yaml","title":"Micro Focus Operations Bridge Manager <=2020.05 - Remote Code Execution","author":"dwisiswant0","disclosed_at":null}],"news":[],"references":[{"url":"https://softwaresupport.softwaregrp.com/doc/KM03747658","source_type":"MISC","tags":[]},{"url":"https://softwaresupport.softwaregrp.com/doc/KM03747657","source_type":"MISC","tags":[]},{"url":"https://softwaresupport.softwaregrp.com/doc/KM03747854","source_type":"MISC","tags":[]},{"url":"https://softwaresupport.softwaregrp.com/doc/KM03749879","source_type":"MISC","tags":[]},{"url":"https://softwaresupport.softwaregrp.com/doc/KM03747949","source_type":"MISC","tags":[]},{"url":"https://softwaresupport.softwaregrp.com/doc/KM03747948","source_type":"MISC","tags":[]},{"url":"https://softwaresupport.softwaregrp.com/doc/KM03747950","source_type":"MISC","tags":[]},{"url":"http://packetstormsecurity.com/files/161182/Micro-Focus-UCMDB-Remote-Code-Execution.html","source_type":"EXPLOIT","tags":["exploit"]},{"url":"http://packetstormsecurity.com/files/161366/Micro-Focus-Operations-Bridge-Manager-Remote-Code-Execution.html","source_type":"EXPLOIT","tags":["exploit"]}],"timeline":[{"type":"published","at":"2020-10-22T20:37:51Z","label":"CVE published","source":null},{"type":"poc_available","at":"2026-06-24T00:29:48.638073Z","label":"Public PoC available","source":"nuclei"},{"type":"cvss_changed","at":"2026-06-28T17:02:06.718090Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:02:06.718090Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:02:06.718090Z","label":"CVSS score revised","source":"cvelistv5"}]}