CVE-2023-28503: Authentication bypass in UniRPC's udadmin service
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28503?
CVE-2023-28503 is an authentication bypass vulnerability in Rocket Software UniData and UniVerse.
How severe is CVE-2023-28503?
CVE-2023-28503 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2023-28503?
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 are affected by CVE-2023-28503.
How can the authentication bypass in CVE-2023-28503 be exploited?
An attacker can leverage a special username with a deterministic password to bypass authentication checks and execute operating system commands.
Are Linux systems affected by CVE-2023-28503?
No, Linux systems are not vulnerable to CVE-2023-28503.