PT-2018-13098 · Reprise · Reprise License Manager
CVE-2018-15573
·
Publicado
2018-08-20
·
Atualizado
2025-04-30
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Reprise License Manager versions through 12.2BL2
Description
An issue was discovered in the Reprise License Manager, where attackers can use the web interface to read and write data to any file on disk, as long as rlm.exe has access to it, via the /goform/edit lf process endpoint with file content in the
lfdata parameter and a pathname in the lf parameter. The web interface, by default, is on port 5054 and does not require authentication.Recommendations
For versions through 12.2BL2, consider disabling access to the /goform/edit lf process endpoint until a resolution is provided. Restrict access to the web interface on port 5054 to minimize the risk of exploitation. Avoid using the
lfdata and lf parameters in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Reprise License Manager