CVE-2022-28365

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
09/04/2022
Last modified:
30/04/2025

Description

Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:* 14.2 (including) 15.1 (excluding)