PT-2023-12322 · Reprise · Reprise License Manager
Blakduk
·
Published
2023-01-20
·
Updated
2025-04-03
·
CVE-2021-37498
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Reprise License Manager (RLM) versions through 14.2BL4
Description
A Server-Side Request Forgery (SSRF) issue was discovered in the Reprise License Manager (RLM) web interface, allowing remote attackers to trigger outbound requests to intranet servers and conduct port scans. This is achieved via the
actserver parameter in the License Activation function.Recommendations
For versions through 14.2BL4, as a temporary workaround, consider restricting access to the License Activation function to minimize the risk of exploitation. Avoid using the
actserver parameter in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Reprise License Manager