Cyber Resilience

CVE-2021-22506

Microfocus Access Manager ≤ 5.0

CISA KEVActive ExploitationEUVD Exploited
Published
26 March 2021
Modified
27 October 2025
KEV Added
03 November 2021
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.26 98th percentile
Risk Priority 84 floored blend · peak EPSS

Summary

CVE-2021-22506 is a high-severity an unspecified weakness vulnerability in Microfocus Access Manager. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The vulnerability is an information leakage issue in the Micro Focus Access Manager product, affecting all versions prior to 5.0 when advanced configuration options are enabled. It is tracked as CVE-2021-22506 with a CVSS 3.1 score of 7.5 reflecting network-accessible attack vectors that require no authentication or user interaction.

An unauthenticated remote attacker can exploit the flaw over the network to obtain sensitive information that would otherwise remain protected, resulting in high confidentiality impact without affecting integrity or availability.

Micro Focus release notes for version 5.0 address the issue through product updates, while CISA includes the CVE in its catalog of known exploited vulnerabilities, confirming active real-world exploitation and the need for prioritized remediation by affected organizations.

EU & UK References

Vulnerability Data

Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage.

CWE(s)
KEV Date Added
03 November 2021

Related Threats

CVEs Like This One

CVE-2026-11877Same product: Microfocus Access Manager
CVE-2026-11878Same product: Microfocus Access Manager
CVE-2021-22502Same vendor: Microfocusboth on KEV
CVE-2023-24467Same vendor: Microfocus
CVE-2024-0622Same vendor: Microfocus
CVE-2024-9841Same vendor: Microfocus
CVE-2024-3969Same vendor: Microfocus
CVE-2023-32265Same vendor: Microfocus
CVE-2024-4429Same vendor: Microfocus
CVE-2023-24469Same vendor: Microfocus

Affected Assets

microfocus
access manager
≤ 5.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References