CVE-2021-22506
Microfocus Access Manager ≤ 5.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NSummary
CVE-2021-22506 is a high-severity an unspecified weakness vulnerability in Microfocus Access Manager. Its CVSS base score is 7.5 (High).
Operationally, ranked in the top 2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The vulnerability is an information leakage issue in the Micro Focus Access Manager product, affecting all versions prior to 5.0 when advanced configuration options are enabled. It is tracked as CVE-2021-22506 with a CVSS 3.1 score of 7.5 reflecting network-accessible attack vectors that require no authentication or user interaction.
An unauthenticated remote attacker can exploit the flaw over the network to obtain sensitive information that would otherwise remain protected, resulting in high confidentiality impact without affecting integrity or availability.
Micro Focus release notes for version 5.0 address the issue through product updates, while CISA includes the CVE in its catalog of known exploited vulnerabilities, confirming active real-world exploitation and the need for prioritized remediation by affected organizations.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-9652
Vulnerability Data
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.
- CWE(s)
- KEV Date Added
- 03 November 2021
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.