Aller au contenu

Fiche vulnérabilité

CVE-2023-28505 : faille élevée Rocket Software UniData (CVSS 8.1)

Description

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
29 mars 2023
Dernière mise à jour
18 févr. 2025

Produits concernés

  • Rocket Software UniData
  • Rocket Software UniVerse

Références

Rechercher une autre vulnérabilité dans la base CVE