CVE-2023-28503
29.03.2023, 21:15
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.Enginsight
Vendor | Product | Version |
---|---|---|
rocketsoftware | unidata | 𝑥 ≤ 8.2.4 |
rocketsoftware | universe | 𝑥 ≤ 11.3.5 |
rocketsoftware | universe | 12.0.0 ≤ 𝑥 ≤ 12.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-798 - Use of Hard-coded CredentialsThe software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
References