CVE-2020-11853: HP Universal Cmbd Foundation

High severity, CVSS 8.8. EPSS: 77% chance of exploitation in the next 30 days.

Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.

Affected products

  • HP Universal Cmbd Foundation: version 10.20 only; version 10.30 only; version 10.31 only; version 10.32 only; version 10.33 only; version 11.0 only; …
  • Micro Focus Application Performance Management: version 9.40 only; version 9.50 only; version 9.51 only
  • Micro Focus Data Center Automation: up to and including 2019.11
  • Micro Focus Hybrid Cloud Management: from 2018.05, up to and including 2020.05
  • Micro Focus Operation Bridge Manager: up to and including 10.10; version 10.11 only; version 10.12 only; version 10.60 only; version 10.61 only; version 10.62 only; …
  • Micro Focus Operations Bridge Manager: version 2017.11 only; version 2018.02 only; version 2018.05 only; version 2018.08 only; version 2018.11 only; version 2019.05 only; …
  • Micro Focus Service Manager Automation: version 2020.02 only; version 2020.05 only

Published 2020-10-22. Last modified 2026-06-17.