Limited Black Friday Offer:
Reprise License Manager 14.2 - Authentication Bypass CVE-2021-44152 Scanner
Reprise License Manager 14.2 allows authentication bypass vulnerability.
Short Info
Level
Critical
Type
Single Scan
Can be used by
Asset Owner
Estimated Time
10 sec
Scan only one
Url
Parent Category
Reprise License Manager 14.2 - Authentication Bypass CVE-2021-44152 Scanner Detail
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.