CVE-2021-37499

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/01/2023
Last modified:
30/04/2025

Description

CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that allows remote attackers to inject arbitrary HTTP headers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:* 17.0 (excluding)