S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-44152 Scanner

CVE-2021-44152 scanner - Authentication Bypass vulnerability in Reprise License Manager

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-44152
9.8
CVSS

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Reprise License Manager is a widely used license manager that offers software license management solutions for businesses and organizations. It is used to manage and track software licenses, control software usage, and monitor license compliance. Reprise License Manager is an essential tool for companies in reducing costs and enforcing compliance with licensing policies. It is relied upon by many organizations as a reliable and secure tool for managing software licenses.

However, a security vulnerability known as CVE-2021-44152 has been discovered in the Reprise RLM version 14.2. This vulnerability is caused by a flaw in the /goform/change_password_process endpoint, which does not verify authentication or authorization. As a result, an attacker could maliciously change the password of any existing user without proper authorization. This could prevent legitimate users from accessing the system and can grant the attacker full access to the user's account.

The exploitation of CVE-2021-44152 can have severe consequences for affected users. Unauthorized access to software licenses can result in a significant financial loss to a company or organization. Not only can this lead to loss of revenue, but it can also affect the business's productivity, as employees will not be able to access the software they need to perform their jobs. This vulnerability could severely damage an organization's reputation, and in extreme cases, it could result in legal action.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. Their professional services provide a comprehensive digital security assessment, identifying the vulnerabilities in websites, networks, and other digital assets. By using their platform, companies can ensure that they are adequately protected against cyber threats and that their digital assets are secure. By taking proactive measures, businesses can reduce the risk of financial loss and reputational damage resulting from cyber attacks.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-44152 vulnerability, certain precautions must be taken. Here are some steps that can be taken to secure Reprise RLM:

  • Upgrade to the latest version of Reprise RLM.
  • Limit access to the Reprise RLM server to only authorized personnel.
  • Use strong passwords that are difficult to guess.
  • Enforce multi-factor authentication to improve authentication security.
  • Monitor the Reprise RLM logs for unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-44152 scanner - Authentication Bypass vulnerability in Reprise License Manager S4E