CVE-2021-22506

HIGH(7.5)KEVElevated Risk

Micro Focus Access Manager Information Leakage Vulnerability

Description

CVE-2021-22506 is a high-severity information leakage vulnerability in Micro Focus Access Manager affecting all versions prior to 5.0 with a CVSS score of 7.5. The vulnerability arises from an advanced configuration issue related to SAML service provider redirection when the Assertion Consumer Service (ACS) URL is used. An unauthenticated remote attacker can exploit this flaw to obtain sensitive information from the Access Manager system without requiring any user interaction. The vulnerability specifically impacts the confidentiality of the system, allowing disclosure of authentication-related data that could be used to facilitate further attacks against the identity management infrastructure.

KEV Information

Vendor
Micro Focus
Product
Micro Focus Access Manager
Date Added
November 3, 2021
Due Date
November 17, 2021
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6

Affected Products

VendorProductVersion
microfocusaccess manager< 5.0

Multiple CVSS Assessments

Source: [email protected](Primary)
7.5
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.5
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

Weakness Type

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CWE-200 describes situations where a product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. In CVE-2021-22506, Micro Focus Access Manager's SAML implementation inadvertently leaks sensitive configuration and authentication data through improper handling of service provider redirections, allowing unauthorized actors to access information that should remain confidential.

Learn more: CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor

Impact Analysis

The impact of CVE-2021-22506 is rated High with a CVSS score of 7.5 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The vulnerability is remotely exploitable over the network with low attack complexity and requires no authentication or user interaction. The primary impact is on confidentiality, rated High, while integrity and availability are not affected. As an identity and access management system, Micro Focus Access Manager handles sensitive authentication data including SAML assertions, session tokens, and user identity information. Information leaked through this vulnerability could enable attackers to impersonate users, hijack sessions, or gain unauthorized access to protected applications that rely on Access Manager for authentication.

Exploit Maturity

CVE-2021-22506 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, added on November 3, 2021, confirming active exploitation in the wild. The EPSS score of 0.105 (93.2nd percentile) indicates a high exploitation probability. While specific public exploit code may not be widely circulated, the presence in the KEV catalog confirms that threat actors have successfully exploited this vulnerability in real-world attacks targeting identity management infrastructure.

Remediation

  1. Upgrade Micro Focus Access Manager to version 5.0 or later immediately, as this version addresses the information leakage vulnerability in the SAML service provider redirection handling.
  2. Review SAML configuration to ensure that Assertion Consumer Service URLs are properly configured and that redirection policies restrict responses to authorized endpoints only.
  3. Audit access logs for the Access Manager system to identify any suspicious authentication patterns, unusual SAML assertion requests, or unexpected redirection activity that could indicate exploitation.
  4. Implement network-level access controls to restrict access to the Access Manager administration and SAML endpoints from untrusted networks.
  5. Rotate SAML certificates and secrets after applying the patch, as sensitive authentication material may have been exposed through the information leakage vulnerability.
  6. Enable comprehensive logging and monitoring for the Access Manager system to detect future attempts to exploit similar information disclosure vectors.

Technical Details

The vulnerability exists in Micro Focus Access Manager's SAML (Security Assertion Markup Language) implementation, specifically in how the system handles service provider redirections involving the Assertion Consumer Service URL. When processing SAML authentication flows, Access Manager improperly handles certain advanced configuration scenarios related to SP-initiated redirections. This improper handling causes the system to leak sensitive information that should not be exposed to unauthenticated requestors. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects that the vulnerability is network-accessible, requires no authentication, and primarily impacts confidentiality. The information leakage could include SAML metadata, configuration details, or authentication tokens that an attacker could leverage to forge SAML assertions or bypass authentication controls. As Access Manager serves as a centralized identity provider, any information leakage from this system has cascading implications for all applications and services that depend on it for authentication and authorization.

Frequently Asked Questions

Is CVE-2021-22506 being actively exploited?

Yes. CVE-2021-22506 is listed in CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The vulnerability targets identity management infrastructure, making it particularly valuable for attackers seeking to compromise authentication systems and gain unauthorized access to protected resources.

What products are affected by CVE-2021-22506?

All versions of Micro Focus Access Manager prior to version 5.0 are affected. The vulnerability is in the SAML service provider redirection handling related to the Assertion Consumer Service URL.

How do I fix CVE-2021-22506?

Upgrade Micro Focus Access Manager to version 5.0 or later. After upgrading, review and audit your SAML configuration, rotate any SAML certificates and secrets, and check access logs for signs of prior exploitation.

How severe is CVE-2021-22506?

With a CVSS score of 7.5 (High), CVE-2021-22506 poses a significant risk. Although it only impacts confidentiality, the nature of the leaked information from an identity management system can enable further attacks including session hijacking, user impersonation, and unauthorized access to any applications that rely on the compromised Access Manager for authentication.

CVSS Score

7.5
HIGH(7.5)

EPSS Score

EPSS Score25.70%
EPSS Percentile97.8%

Dates

PublishedMarch 26, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.