Rocket Software UniVerse 12.2.1

CPE Details

Rocket Software UniVerse 12.2.1
12.2.1
2023-04-04
13h42 +00:00
2023-07-17
12h16 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:rocketsoftware:universe:12.2.1:*:*:*:*:*:*:*

Informations

Vendor

rocketsoftware

Product

universe

Version

12.2.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-28509 2023-03-29 20h18 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.
7.5
Haute
CVE-2023-28508 2023-03-29 20h16 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.
8.8
Haute
CVE-2023-28507 2023-03-29 20h15 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.
9.8
Critique
CVE-2023-28506 2023-03-29 20h13 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.
8.8
Haute
CVE-2023-28505 2023-03-29 20h12 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.
8.8
Haute
CVE-2023-28504 2023-03-29 20h11 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.
9.8
Critique
CVE-2023-28503 2023-03-29 20h09 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.
9.8
Critique
CVE-2023-28502 2023-03-29 20h03 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.
9.8
Critique
CVE-2023-28501 2023-03-29 19h54 +00:00 Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.
9.8
Critique