← Back to browse · API

CVE-2023-28503

Severity
CRITICAL
CVSS
9.8
EPSS
0.62136
Risk score
60.95
CISA KEV
No
PoC
No
Published
2023-03-29
Modified
2025-02-18
First seen
2026-08-07
Aliases
EUVD-2023-32173, GHSA-G594-6376-7C5R
Products
Rocket Software:UniData 0 <8.2.43.3003, Rocket Software:UniVerse 0 <11.3.5.1001, Rocket Software:UniVerse 0 <12.2.1.2002
Sources
euvd EUVD-2023-32173

Description

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

References