Vulnerability Description
A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the Operations Bridge Manager capability is deployed. A potential vulnerability has been identified in Micro Focus Operations Bridge Manager (OBM). The vulnerability could be exploited by a malicious authenticated OBM user to run Java Scripts in the browser context of another OBM user. This issue affects: Micro Focus Micro Focus Operations Bridge Manager versions prior to 2022.11. Micro Focus Micro Focus Operations Bridge- Containerized versions prior to 2022.11.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Operations Bridge | < 2022.11 |
| Microfocus | Operations Bridge Manager | < 2022.11 |
Related Weaknesses (CWE)
References
- https://marketplace.microfocus.com/itom/content/operations-bridge-manager-obm-20
- https://portal.microfocus.com/s/article/KM000012517?language=en_US
- https://portal.microfocus.com/s/article/KM000012518?language=en_US
- https://marketplace.microfocus.com/itom/content/operations-bridge-manager-obm-20
- https://portal.microfocus.com/s/article/KM000012517?language=en_US
- https://portal.microfocus.com/s/article/KM000012518?language=en_US
FAQ
What is CVE-2022-38754?
CVE-2022-38754 is a vulnerability with a CVSS score of 8.0 (HIGH). A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user t...
How severe is CVE-2022-38754?
CVE-2022-38754 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38754?
Check the references section above for vendor advisories and patch information. Affected products include: Microfocus Operations Bridge, Microfocus Operations Bridge Manager.