Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 18 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2025-02-18T16:05:42.549Z

Reserved: 2023-03-16T20:44:20.345Z

Link: CVE-2023-28503

cve-icon Vulnrichment

Updated: 2024-08-02T13:43:22.599Z

cve-icon NVD

Status : Modified

Published: 2023-03-29T21:15:08.123

Modified: 2025-02-18T16:15:15.190

Link: CVE-2023-28503

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.