imPC@ndo IT

Tracker / CVE-2023-28503

CVE-2023-28503

Critical 9.8

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

Affected products and versions

rocketsoftware unidata · … → 8.2.4
rocketsoftware universe · … → 11.3.5
rocketsoftware universe · 12.0.0 → 12.2.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References