漏洞描述
Reprise License Manager (RLM) 14.2 does not verify authentication or authorization and allows unauthenticated users to change the password of any existing user.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
reprisesoftware.comhttps://reprisesoftware.com/admin/rlm-admin-download.php?&euagree=yes↗packetstormsecurity.comhttp://packetstormsecurity.com/files/165186/Reprise-License-Manager-14.2-Unauthenticated-Password-Change.html↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-44152↗www.reprisesoftware.comhttps://www.reprisesoftware.com/RELEASE_NOTES↗github.comhttps://github.com/anonymous364872/Rapier_Tool↗