PT-2023-12322 · Reprise · Reprise License Manager

Blakduk

·

Published

2023-01-20

·

Updated

2025-04-03

·

CVE-2021-37498

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Reprise License Manager (RLM) versions through 14.2BL4
Description A Server-Side Request Forgery (SSRF) issue was discovered in the Reprise License Manager (RLM) web interface, allowing remote attackers to trigger outbound requests to intranet servers and conduct port scans. This is achieved via the actserver parameter in the License Activation function.
Recommendations For versions through 14.2BL4, as a temporary workaround, consider restricting access to the License Activation function to minimize the risk of exploitation. Avoid using the actserver parameter in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37498

Affected Products

Reprise License Manager