5.3

CVE-2022-28365

Exploit
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ReprisesoftwareReprise License Manager Version >= 14.2 < 15.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.99% 0.94
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

https://www.reprisesoftware.com/RELEASE_NOTES
Broken Link
http://packetstormsecurity.com/files/166647/Reprise-License-Manager-14.2-Cross-Site-Scripting-Information-Disclosure.html
Third Party Advisory
Exploit
VDB Entry
https://seclists.org/fulldisclosure/2022/Apr/1
Third Party Advisory
Exploit
Mailing List
https://www.reprisesoftware.com/products/software-license-management.php
Product