icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

Rocket Software UniVerse < 10.3.9 Remote Code Execution Vulnerability

Synopsis

The remote host contains a database application that is affected by a remote code execution vulnerability.

Description

The remote host has Rocket Software UniVerse installed.

Versions of UniVerse earlier than 10.3.9 are potentially affected by a remote code execution vulnerability because the application fails to properly validate a size value in a RPC packet header before using it to determine the number of bytes to receive. A remote unauthenticated attacker, exploiting this flaw, could execute arbitrary code on the remote host with SYSTEM level privileges.

Solution

Upgrade to UniVerse 10.3.9 or later.