VYPR

Snow License Manager

by Snow Software

CVEs (4)

  • CVE-2024-4129HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0.

  • CVE-2023-3864HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.

  • CVE-2022-0883HigMay 18, 2022
    risk 0.47cvss 7.3epss 0.00

    SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.

  • CVE-2023-3937MedAug 11, 2023
    risk 0.31cvss 4.8epss 0.00

    Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser