CVE-2020-11854: Micro Focus Application Performance Management

Critical severity, CVSS 9.8. EPSS: 74.4% chance of exploitation in the next 30 days.

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

Affected products

  • Micro Focus Application Performance Management: version 9.50 only; version 9.51 only; version 9.40 only
  • Micro Focus Operations Bridge: version 2017.11 only; version 2018.02 only; version 2018.05 only; version 2018.08 only; version 2018.11 only; version 2019.05 only; …
  • Micro Focus Operations Bridge Manager: up to and including 10.10; version 10.11 only; version 10.12 only; version 10.60 only; version 10.61 only; version 10.62 only; …

Published 2020-10-27. Last modified 2026-06-17.