Rocket Software UniData versions prior to 8.2.4 build...
Critical severity
Unreviewed
Published
Mar 29, 2023
to the GitHub Advisory Database
•
Updated Feb 18, 2025
Description
Published by the National Vulnerability Database
Mar 29, 2023
Published to the GitHub Advisory Database
Mar 29, 2023
Last updated
Feb 18, 2025
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.
References