reprisesoftware CVE Vulnerabilities & Metrics

Focus on reprisesoftware vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About reprisesoftware Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with reprisesoftware. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total reprisesoftware CVEs: 17
Earliest CVE date: 21 Feb 2018, 15:29 UTC
Latest CVE date: 03 Mar 2025, 19:15 UTC

Latest CVE reference: CVE-2025-25939

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical reprisesoftware CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.25

Max CVSS: 9.3

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 7
7.0-8.9 2
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS reprisesoftware CVEs

These are the five CVEs with the highest CVSS scores for reprisesoftware, sorted by severity first and recency.

All CVEs for reprisesoftware

CVE-2025-25939 reprisesoftware vulnerability CVSS: 0 03 Mar 2025, 19:15 UTC

Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.

CVE-2021-37500 reprisesoftware vulnerability CVSS: 0 20 Jan 2023, 12:15 UTC

Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to overwrite any file the on the server.

CVE-2021-37499 reprisesoftware vulnerability CVSS: 0 20 Jan 2023, 12:15 UTC

CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that allows remote attackers to inject arbitrary HTTP headers.

CVE-2021-37498 reprisesoftware vulnerability CVSS: 0 20 Jan 2023, 12:15 UTC

An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function.

CVE-2022-30519 reprisesoftware vulnerability CVSS: 0 29 Dec 2022, 23:15 UTC

XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.

CVE-2022-28365 reprisesoftware vulnerability CVSS: 5.0 09 Apr 2022, 17:15 UTC

Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.

CVE-2022-28364 reprisesoftware vulnerability CVSS: 3.5 09 Apr 2022, 17:15 UTC

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.

CVE-2022-28363 reprisesoftware vulnerability CVSS: 4.3 09 Apr 2022, 17:15 UTC

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.

CVE-2021-45422 reprisesoftware vulnerability CVSS: 4.3 13 Jan 2022, 19:15 UTC

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required.

CVE-2021-44155 reprisesoftware vulnerability CVSS: 5.0 13 Dec 2021, 04:15 UTC

An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an attacker to enumerate valid users.

CVE-2021-44154 reprisesoftware vulnerability CVSS: 6.5 13 Dec 2021, 04:15 UTC

An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_opt, which will then be triggered when running the diagnostics (via /goform/diagnostics_doit), resulting in a buffer overflow.

CVE-2021-44153 reprisesoftware vulnerability CVSS: 9.0 13 Dec 2021, 04:15 UTC

An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable an option to run arbitrary executables, as demonstrated by an ISV demo "C:\Windows\System32\calc.exe" entry. An attacker can exploit this to run a malicious binary on startup, or when triggering the Reread/Restart Servers function on the webserver. (Exploitation does not require CVE-2018-15573, because the license file is meant to be changed in the application.)

CVE-2021-44152 reprisesoftware vulnerability CVSS: 7.5 13 Dec 2021, 04:15 UTC

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

CVE-2021-44151 reprisesoftware vulnerability CVSS: 5.0 13 Dec 2021, 04:15 UTC

An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version appears to have 8 characters). An attacker can obtain the static part of the cookie (cookie name) by first making a request to any page on the application (e.g., /goforms/menu) and saving the name of the cookie sent with the response. The attacker can then use the name of the cookie and try to request that same page, setting a random value for the cookie. If any user has an active session, the page should return with the authorized content, when a valid cookie value is hit.

CVE-2018-15574 reprisesoftware vulnerability CVSS: 4.3 20 Aug 2018, 02:29 UTC

An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability."

CVE-2018-15573 reprisesoftware vulnerability CVSS: 9.3 20 Aug 2018, 02:29 UTC

An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /goform/edit_lf_process with file content in the lfdata parameter and a pathname in the lf parameter. By default, the web interface is on port 5054, and does not require authentication. NOTE: the vendor has stated "We do not consider this a vulnerability.

CVE-2018-5716 reprisesoftware vulnerability CVSS: 8.5 21 Feb 2018, 15:29 UTC

An issue was discovered in Reprise License Manager 11.0. This vulnerability is a Path Traversal where the attacker, by changing a field in the Web Request, can have access to files on the File System of the Server. By specifying a pathname in the POST parameter "lf" to the goform/edit_lf_get_data URI, the attacker can retrieve the content of a file.