CVE-2021-37498

An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:*

History

03 Apr 2025, 13:15

Type Values Removed Values Added
References (MISC) http://reprise.com - Not Applicable () http://reprise.com - Not Applicable
References (MISC) http://reprisesoftware.com - Product () http://reprisesoftware.com - Product
References (MISC) https://github.com/blakduk/Advisories/blob/main/Reprise%20License%20Manager/README.md - Third Party Advisory () https://github.com/blakduk/Advisories/blob/main/Reprise%20License%20Manager/README.md - Third Party Advisory

Information

Published : 2023-01-20 12:15

Updated : 2025-04-30 21:03


NVD link : CVE-2021-37498

Mitre link : CVE-2021-37498


JSON object : View

Products Affected

reprisesoftware

  • reprise_license_manager
CWE
CWE-918

Server-Side Request Forgery (SSRF)