← Back

CVE-2021-44155

nvd nist
Published: Dec 13, 2021Modified: Apr 30, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an attacker to enumerate valid users.

Affected (1)

Reprise License Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 14.2 to 15.1

References (6)

Source: cve@mitre.org
PatchProductVendor Advisory
Source: cve@mitre.org
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link

Timeline

No history available yet.