Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-15573

Опубликовано: 20 авг. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 9.3
EPSS Низкий

Описание

An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /goform/edit_lf_process with file content in the lfdata parameter and a pathname in the lf parameter. By default, the web interface is on port 5054, and does not require authentication. NOTE: the vendor has stated "We do not consider this a vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:*
Версия до 16.1 (исключая)

EPSS

Процентиль: 72%
0.00716
Низкий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

** DISPUTED ** An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /goform/edit_lf_process with file content in the lfdata parameter and a pathname in the lf parameter. By default, the web interface is on port 5054, and does not require authentication. NOTE: the vendor has stated "We do not consider this a vulnerability."

EPSS

Процентиль: 72%
0.00716
Низкий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-434