An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/165186/Reprise-License-Manager-14.2-Unauthenticated-Password-Change.html | Exploit Third Party Advisory VDB Entry |
https://reprisesoftware.com/admin/rlm-admin-download.php?&euagree=yes | Patch Product Vendor Advisory |
https://www.reprisesoftware.com/RELEASE_NOTES | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-12-13T00:00:00
Updated: 2023-04-20T00:00:00
Reserved: 2021-11-22T00:00:00
Link: CVE-2021-44152
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-12-13T04:15:07.180
Modified: 2023-08-02T17:28:30.623
Link: CVE-2021-44152
JSON object: View
Redhat Information
No data.
CWE