MFSBGN03798 rev.1 - Micro Focus Universal CMDB, Apache Struts Instance
Description
Universal CMDB 4.10-4.12 contains a remote code execution vulnerability via an unspecified Apache Struts instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Universal CMDB 4.10-4.12 contains a remote code execution vulnerability via an unspecified Apache Struts instance.
Vulnerability
An arbitrary code execution vulnerability exists in Micro Focus Universal CMDB versions 4.10, 4.11, and 4.12. The flaw resides within an Apache Struts instance integrated into the UCMDB Configuration Manager component, as documented in the security bulletin [1]. The exact component within the UCMDB product is not further specified, but the vector is remotely exploitable without authentication [1].
Exploitation
An attacker can exploit this vulnerability remotely over the network. The CVSS v3 attack vector is AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating that while the attack complexity is high (some specialized conditions or configuration may be required), no privileges or user interaction are needed [1]. The specific steps are not detailed in the available references, but the vector suggests network-based input to the Apache Struts instance suffices.
Impact
Successful exploitation results in arbitrary code execution on the affected server. The CVSS v3 confidentiality, integrity, and availability impacts are all rated High [1]. An attacker can fully compromise the UCMDB server, gaining the ability to execute arbitrary commands with the privileges of the UCMDB service account.
Mitigation
Micro Fixed has released a fix. The security bulletin (Document ID KM03086019) from 21-Feb-2018 provides remediation guidance [1]. Users are advised to apply the vendor-supplied patch or update to a fixed version beyond 4.12. No workarounds are disclosed in the available reference.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 4.10, 4.11, 4.12
- Micro Focus/Micro Focus Universal CMDBv5Range: 4.10, 4.11, 4.12
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03086019mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.