578
VMScore

CVE-2021-44154

Published: 13/12/2021 Updated: 15/12/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_opt, which will then be triggered when running the diagnostics (via /goform/diagnostics_doit), resulting in a buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

reprisesoftware reprise license manager 14.2

Exploits

Reprise License Manager version 142 suffers from an authenticated buffer overflow vulnerability ...