9.8
CVSSv3

CVE-2021-44152

Published: 13/12/2021 Updated: 02/08/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an malicious user to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

reprisesoftware reprise license manager

Exploits

Reprise License Manager version 142 suffers from a missing authentication vulnerability that allows for password changing of any existing user ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> (Reprise License Manager) RLM 142 - Unauthenticated Password Change <!--X-Subject-Header-End--> <!--X-Head-of-Message ...