5.3
CVSSv3

CVE-2021-44155

Published: 13/12/2021 Updated: 20/04/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an malicious user to enumerate valid users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

reprisesoftware reprise license manager 14.2

Exploits

Reprise License Manager version 142 suffers from a user enumeration vulnerability ...