Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:reprisesoftware:reprise_license_manager:14.2:*:*:*:*:*:*:*", "matchCriteriaId": "7398E968-24AF-4006-92A0-B9DDC49EF43D", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an attacker to enumerate valid users."}, {"lang": "es", "value": "Se ha detectado un problema en /goform/login_process en Reprise RLM versi\u00f3n 14.2. Cuando un atacante intenta iniciar sesi\u00f3n, la respuesta si un nombre de usuario es v\u00e1lido incluye Login Failed, pero no incluye esta cadena si el nombre de usuario no es v\u00e1lido. Esto permite a un atacante enumerar usuarios v\u00e1lidos"}], "id": "CVE-2021-44155", "lastModified": "2024-11-21T06:30:27.750", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "version": "2.0"}, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1"}, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2021-12-13T04:15:07.323", "references": [{"source": "cve@mitre.org", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "url": "http://packetstormsecurity.com/files/165182/Reprise-License-Manager-14.2-User-Enumeration.html"}, {"source": "cve@mitre.org", "tags": ["Patch", "Product", "Vendor Advisory"], "url": "https://reprisesoftware.com/admin/rlm-admin-download.php?&euagree=yes"}, {"source": "cve@mitre.org", "url": "https://www.reprisesoftware.com/RELEASE_NOTES"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Third Party Advisory", "VDB Entry"], "url": "http://packetstormsecurity.com/files/165182/Reprise-License-Manager-14.2-User-Enumeration.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch", "Product", "Vendor Advisory"], "url": "https://reprisesoftware.com/admin/rlm-admin-download.php?&euagree=yes"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.reprisesoftware.com/RELEASE_NOTES"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-209"}], "source": "nvd@nist.gov", "type": "Primary"}]}