reprisesoftware Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with reprisesoftware products.
Products
- reprise_license_manager3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-28363MEDIUM | reprisesoftware reprise_license_manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required. | CVSS6.1v3.1 | EPSS4.92% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-28365MEDIUM | reprisesoftware reprise_license_manager Direct Request ('Forced Browsing')Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details. | CVSS5.3v3.1 | EPSS9.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-45422MEDIUM | reprisesoftware reprise_license_manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required. | CVSS6.1v3.1 | EPSS3.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |