Summary
A remote code execution (RCE) vulnerability was identified in the FlexNet Publisher lmadmin web user interface. This vulnerability is addressed in the FlexNet Publisher 2023 R2 (11.19.4.0) release.
Symptoms
If exploited, the vulnerability allows the execution of a rogue vendor daemon using the UNC path.
NOTE: This vulnerability does not impact the lmgrd utility.
Steps to Reproduce
For security reasons, we will not publish details for reproducing the vulnerability.
Workaround
We advise users to upgrade their lmadmin to 11.19.4.0 or greater. If users are unable to upgrade, license server administrators may start lmadmin with the -noweb option to disable the lmadmin web module. This prevents lmadmin from being accessed through a web browser and it will only be accessible via the console.
Fix Version and Resolution
The vulnerability is addressed in FlexNet Publisher 2023 R2 (11.19.4.0) which was released on May 17, 2023. Users are advised to upgrade their lmadmin to 11.19.4.0 or greater. License server administrators may download the latest lmadmin from the FlexNet Publisher lmadmin download links page.
Additional Information
For identifying this vulnerability and disclosing it to Revenera under a responsible disclosure process, we would like to thank and credit Mattias Dewulf, co-founder of Spinae.
Related Articles
Apache Log4j remote code execution vulnerability CVE-2021-44228 with Spider OneSearch rely on Enterprise Service Infrastru… 5Number of Views FlexNet Beacon vulnerability remediated in FlexNet Manager Suite 5Number of Views CVE-2018-20033 Remediated in FlexNet Publisher 8Number of Views CVE-2024-9389: Data Platform User Console Command Execution Vulnerability 6Number of Views CVE-2020-12082 Remediated in Code Insight 3Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago