CVE-2022-28365
Reprise License Manager 14.2 Cross Site Scripting / Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.
Reprise License Manager versión 14.2, está afectado por una vulnerabilidad de divulgación de información por medio de una petición GET a /goforms/rlminfo. No es requerida autenticación. La información divulgada está asociada a versiones de software, IDs de procesos, configuración de red, nombre(s) de host, arquitectura del sistema y detalles de archivos/directorios
Reprise License Manager version 14.2 suffers from cross site scripting and information disclosure vulnerabilities. The vendor has contacted Packet Storm to note that in v15.1 they have fixed this issue by now requiring login for the rlminfo route.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-03 CVE Reserved
- 2022-04-08 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-425: Direct Request ('Forced Browsing')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.reprisesoftware.com/RELEASE_NOTES | ||
https://www.reprisesoftware.com/products/software-license-management.php | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Reprisesoftware Search vendor "Reprisesoftware" | Reprise License Manager Search vendor "Reprisesoftware" for product "Reprise License Manager" | 14.2 Search vendor "Reprisesoftware" for product "Reprise License Manager" and version "14.2" | - |
Affected
|