IT

Tracker / CVE-2023-28505

CVE-2023-28505

High 8.8

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.

Affected products and versions

rocketsoftware unidata · … → 8.2.4
rocketsoftware universe · … → 11.3.5
rocketsoftware universe · 12.0.0 → 12.2.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References