Summary
A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.
Affected Products
The vulnerability affects the FlexNet Publisher lmadmin version 11.19.11 and earlier.
Remediation
Administrator authentication is now properly enforced for all administrative operations, ensuring that only authenticated and authorized users can access privileged administrative functionality.
Fix
Revenera has fixed this vulnerability in FlexNet Publisher lmadmin 11.19.11.1. Customers using affected versions are encouraged to upgrade to lmadmin 11.19.11.1 to obtain the security fix. The latest lmadmin version can be downloaded from the FlexNet Publisher lmadmin Download Links article.
Additional Information
Credited: For identifying this issue and disclosing it to Revenera PSIRT under the responsible disclosure process, we'd like to credit Ryan Wincey (@rwincey) of Securifera.
Related Articles
FlexNet Publisher lmadmin Download Links 50Number of Views FlexNet Publisher lmadmin: Denial of Service Vulnerability Discovered 10Number of Views IMPORTANT NOTICE: Possible Security Vulnerability in FlexNet Publisher lmadmin License Server Manager 9Number of Views FlexNet Publisher lmadmin: Security Vulnerability CVE-2022-23308 Detected in Modsecurity Component 8Number of Views Impact of CVE-2017-5571 : Open Redirect Vulnerability in lmadmin Component of Flexera FlexNet Publisher 9Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago