An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function.
References
Link | Resource |
---|---|
http://reprise.com | Not Applicable |
http://reprisesoftware.com | Product |
https://github.com/blakduk/Advisories/blob/main/Reprise%20License%20Manager/README.md | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-01-20T00:00:00
Updated: 2023-01-20T00:00:00
Reserved: 2021-07-26T00:00:00
Link: CVE-2021-37498
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-01-20T12:15:10.143
Modified: 2023-01-27T14:27:42.440
Link: CVE-2021-37498
JSON object: View
Redhat Information
No data.
CWE