CVE-2021-37498
Summary
| CVE | CVE-2021-37498 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-20 12:15:00 UTC |
| Updated | 2023-01-27 14:27:00 UTC |
| Description | An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Reprisesoftware | Reprise License Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Software License Management, Activation and Cloud Licensing. | Reprise Software | MISC | reprisesoftware.com | |
| Advisories/README.md at main · blakduk/Advisories · GitHub | MISC | github.com | |
| Reprise — Create Winning Demos | MISC | reprise.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.