Reprisesoftware's vulnerability footprint centers on its Reprise License Manager, a widely deployed licensing and access-control platform that sits in the software supply chain across enterprises. The vendor's exposure recurs through application-layer and input-handling weakness classes including cross-site scripting, path traversal, classic buffer overflow, and forced browsing, reflecting the web-interface and file-access responsibilities of a license-administration service. A meaningful share of the vendor's disclosures have acquired public exploit code; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reprisesoftware over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44152CRITICAL An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the passwor | Dec 13, 2021 | 9.8 | 74 | NO | YES |
CVE-2022-28365MEDIUM Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed | Apr 9, 2022 | 5.3 | 34 | NO | YES |
CVE-2022-28363MEDIUM Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is requi | Apr 9, 2022 | 6.1 | 34 | NO | YES |
CVE-2021-45422MEDIUM Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required. | Jan 13, 2022 | 6.1 | 34 | NO | YES |
CVE-2022-30519MEDIUM XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field. | Dec 29, 2022 | 6.1 | 31 | NO | YES |
CVE-2021-37500HIGH Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to over | Jan 20, 2023 | 8.1 | 29 | NO | NO |
CVE-2018-15573HIGH An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has acc | Aug 20, 2018 | 8.8 | 27 | NO | NO |
CVE-2023-43183HIGH Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows read-only users to arbitrarily change the password of an admin and hijack their | Feb 3, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-37499MEDIUM CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that allows remote attackers to inject | Jan 20, 2023 | 6.5 | 25 | NO | NO |
CVE-2021-37498MEDIUM An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct p | Jan 20, 2023 | 6.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reprisesoftware.
Media articles that mention a CVE ID that affects a product developed by Reprisesoftware — matched by CVE ID, not by vendor name.