VYPR

Reprise License Manager

by Reprise Software

CVEs (5)

  • CVE-2018-15573HigAug 20, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /goform/edit_lf_process with file content in the lfdata parameter and a pathname in…

  • CVE-2022-28363MedApr 9, 2022
    risk 0.40cvss 6.1epss 0.05

    Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.

  • CVE-2018-15574MedAug 20, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability."

  • CVE-2022-28365MedApr 9, 2022
    risk 0.35cvss 5.3epss 0.09

    Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system…

  • CVE-2022-28364MedApr 9, 2022
    risk 0.35cvss 5.4epss 0.01

    Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.