PT-2024-13077 · Reprise · Reprise License Manager
Mohaiman Rahim
·
Published
2024-02-03
·
Updated
2025-05-15
·
CVE-2023-43183
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Reprise License Manager version 15.1
Description
The issue allows read-only users to arbitrarily change the password of an admin and hijack their account due to incorrect access control in Reprise License Management Software.
Recommendations
For Reprise License Manager version 15.1, consider restricting access to password change functionality for read-only users until a patch is available. As a temporary workaround, monitor account activity closely to detect potential hijacking attempts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Reprise License Manager