CVE-2021-37499
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/01/2023
Last modified:
30/04/2025
Description
CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that allows remote attackers to inject arbitrary HTTP headers.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:* | 17.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



