ZeroHour

CVE-2021-37498

CVSS 3.1
6.5 medium
EPSS
<1%p47
Published
()
Modified
Description

An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function.

Vendors
reprisesoftware
Products
reprise license manager
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.