CVE-2021-37498

An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema SSRF en la interfaz web de Reprise License Manager (RLM) hasta 14.2BL4 que permite a atacantes remotos activar solicitudes salientes a servidores de intranet y realizar escaneos de puertos a través del parámetro acterver en la función Activación de licencia.
References () http://reprise.com - Not Applicable () http://reprise.com - Not Applicable
References () http://reprisesoftware.com - Product () http://reprisesoftware.com - Product
References () https://github.com/blakduk/Advisories/blob/main/Reprise%20License%20Manager/README.md - Third Party Advisory () https://github.com/blakduk/Advisories/blob/main/Reprise%20License%20Manager/README.md - Third Party Advisory

Information

Published : 2023-01-20 12:15

Updated : 2024-11-21 06:15


NVD link : CVE-2021-37498

Mitre link : CVE-2021-37498

CVE.ORG link : CVE-2021-37498


JSON object : View

Products Affected

reprisesoftware

  • reprise_license_manager
CWE
CWE-918

Server-Side Request Forgery (SSRF)