CVE-2021-37498

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
20/01/2023
Last modified:
30/04/2025

Description

An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:* 17.0 (excluding)