Rocket U2 | UniVerse & UniData

 View Only
Expand all | Collapse all

UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

  • 1.  UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    ROCKETEER
    Posted 03-29-2023 14:59

    At Rocket Software we are committed to and value product security.  Rocket Software continually reviews security compliance policies and trends to strengthen our products. We've  recently implemented the Rocket Vulnerability Disclosure Program (VDP) as an added measure of vigilance.  This program allows us to collaborate with valued researchers to respond to vulnerabilities found in Rocket Software products and resolve them on behalf of our customers.

    Recently, Rapid7 Research discovered several vulnerabilities in Rocket UniData 8.2.4 and reported them through the VDP.  Rapid7 found vulnerabilities with the UniData UniRPC server (and related services) running on the Linux platform.  Due to the nature of the MultiValue applications, Rapid7 believes that widespread exploitation of the vulnerabilities is unlikely; these services tend to be found on the backend and are rarely internet-facing.  That being said, the software stack is commonly used by large organizations to store and manage data, so it's possible that these vulnerabilities will be exploited by attackers who have already gained unauthorized access to an organization's network in another way. 

    Remediation

    The Rocket Software MultiValue team reviewed Rapid7's findings and worked closely with them to identify and resolve the UniRPC security vulnerabilities in UniData 8.2.4.  After completing internal testing across the U2 data servers, the MultiValue team also identified and resolved the vulnerabilities in UniVerse 11.3.5 & 12.2.1. 

    The Rapid7 Vulnerability Disclosure will be posted to the Rapid7 Research blog on March 30, 2023.  Please review this blog post and the hotfix release notes for more vulnerability and remediation details.

    If you are running Rocket UniData or Rocket UniVerse, regardless of the version, we strongly advise you to upgrade to the latest hotfixes, available on Rocket Business Connect (rbc.rocketsoftware.com):

    ·        UniData 8.2.4.3003

    ·        UniVerse 11.3.5.1001

    UniVerse 12.2.1.2002 (available by April 14, 2023)



    ------------------------------
    Christine Rizza
    Sr. MV Product Manager
    Rocket Software
    crizza@rocketsoftware.com
    ------------------------------


  • 2.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    PARTNER
    Posted 03-30-2023 02:05

    Thanks for posting this @Christine Rizza 

    The Rapid7 blog post indicates that Rocket had confirmed that the vulnerability affected both "UniVerse 11.3.5 (and earlier)" and "UniVerse 12.2.1 (and earlier)".

    There was no explicit mention of UniVerse 11.2.x versions as being affected.

    Is that because it falls under the "11.3.5 and earlier" category (so it IS affected), or it has been checked and is not vulnerable?



    ------------------------------
    Gregor Scott
    Software Architect
    Pentana Solutions Pty Ltd
    Mount Waverley VIC AU
    ------------------------------



  • 3.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    ROCKETEER
    Posted 03-30-2023 10:25

    Gregor,

    Although the vulnerabilities were found by Rapid7 by checking UniData 8.2.4, we tested and fixed them in UniVerse 11.3.5 and 12.2.1.  We expect the vulnerabilities also exist in all the EOM 11.2 versions.  Note that all versions of UV 11.2 will be EOS/EOLS in September 2023.  We only tested and fixed against the current GA versions of UniVerse which is in line with the Rocket MV Product Lifecycle Status Policy.  In the Rocket announcement we do strongly advise customers to upgrade to the hotfixes regardless of the version they are running.



    ------------------------------
    Christine Rizza
    Sr. MV Product Manager
    Rocket Software
    crizza@rocketsoftware.com
    ------------------------------



  • 4.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    PARTNER
    Posted 03-30-2023 10:12

    Good morning Christine,

    Is there a hotfix for UniVerse versions?  If yes, which versions are covered?  If no, is one planned and, again, which versions will be covered?

    Thanks,



    ------------------------------
    Tyrel Marak
    Technical Support Manager
    Aptron Corporation
    Florham Park NJ US
    ------------------------------



  • 5.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    ROCKETEER
    Posted 03-30-2023 10:27

    Hi Tyrel,

    Yes, there are hotfixes:

    If you are running Rocket UniData or Rocket UniVerse, regardless of the version, we strongly advise you to upgrade to the latest hotfixes, available on Rocket Business Connect (rbc.rocketsoftware.com):

    • UniData 8.2.4.3003
    • UniVerse 11.3.5.1001
    • UniVerse 12.2.1.2002 (available by April 14, 2023)


    ------------------------------
    Christine Rizza
    Sr. MV Product Manager
    Rocket Software
    crizza@rocketsoftware.com
    ------------------------------



  • 6.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    Posted 03-30-2023 10:39
    How do we know what UniData version we are on? 8.2.4.3003, it’s the 3003 part I am asking about.




  • 7.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    ROCKETEER
    Posted 03-30-2023 10:59

    The simplist way is to check in the port.note file in the $UDTBIN directory the version number is at the end of the UniData Release (see below)

    Platform         : AIX 7.1 - 64bit
    Operating System : AIX dendevmvasbld03 1 7 00FA6E984C00 7100-05-03-1837
    Porting Date     : Thu Sep 22 00:39:36 EDT 2022
    UniData Release  : 8.2.4 82_220921_3001
    Ported by        : svnsrc
    Compilers Used   : IBM XL C/C++ for AIX, V10.1
                       Version: 10.01.0000.0008
    Revision         : 2338869

    So the example machine is running 8.2.4.3001



    ------------------------------
    Jonathan Smith
    UniData ATS
    Rocket Support
    ------------------------------



  • 8.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    Posted 03-30-2023 11:32
    Thanks!




  • 9.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    PARTNER
    Posted 03-30-2023 17:12

    The original report specifically mentions Linux versions. Can anyone confirm that the vulnerability also exists on other Unix-like platforms (such as AIX)?



    ------------------------------
    Martin Shields
    Senior Technical Consultant
    Meier Business Systems PTY LTD
    Carnegie VIC AU
    ------------------------------



  • 10.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    PARTNER
    Posted 03-30-2023 10:49

    Thank you Chris,

    Just to be clear, the UniVerse 11.3.5.1001 hotfix will work for a site running 11.3.2.7003?  Or do they need to upgrade to 11.3.5 and then apply the hotfix?



    ------------------------------
    Tyrel Marak
    Technical Support Manager
    Aptron Corporation
    Florham Park NJ US
    ------------------------------



  • 11.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    ROCKETEER
    Posted 03-30-2023 10:58

    Hi Tyrel,

    The 11.3.5.1001 hotfix release is a full release. No need to install 11.3.5 first.

    Thanks,

    Neil



    ------------------------------
    Neil Morris
    Universe Advanced Technical Support
    Rocket Software
    ------------------------------



  • 12.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    Posted 03-30-2023 12:04
    Will there be hotfixes released for the other 11.3.? releases or will we need to upgrade to 11.3.5.1001?

    Steve




  • 13.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    ROCKETEER
    Posted 03-30-2023 15:48

    Steve,

    We are only patching the current GA releases of both UniData and UniVerse and do not plan to hotfix older versions.  We do encourage our customers to upgrade to current GA releases so that they can take full advantage of all enhancements and bug fixes as well as stay up to date with security compliance standards, updates, and vulnerability fixes.



    ------------------------------
    Christine Rizza
    Sr. MV Product Manager
    Rocket Software
    crizza@rocketsoftware.com
    ------------------------------



  • 14.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    PARTNER
    Posted 03-30-2023 18:10

    Hi Chris,

    Can you clarify please whether or not the vulnerability exists for Universe running on AIX 7.1 and/or AIX 7.2?



    ------------------------------
    John Green
    Head of Technology
    Ultradata Australia Pty Ltd
    Malvern East VIC AU
    ------------------------------



  • 15.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    ROCKETEER
    Posted 03-31-2023 04:14

    Although Rapid7 found the vulnerabilities while looking on a Linux installation the vulnerabilities exist on all platforms.



    ------------------------------
    Jonathan Smith
    UniData ATS
    Rocket Support
    ------------------------------



  • 16.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    PARTNER
    Posted 03-31-2023 09:03

    Jonathan,

    I think you mean all UNIX/Linux platforms, right?  Or has Rocket discovered that the vulnerabilities extend to Windows? 

    Rapid7:  We verified that these issues do not affect the Windows version, as the networking stack appears to be different.

    I'm not trying to be overly pedantic; we've been planning based on the Rapid7 blog post.

    Thanks,



    ------------------------------
    Tyrel Marak
    Technical Support Manager
    Aptron Corporation
    Florham Park NJ US
    ------------------------------



  • 17.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    ROCKETEER
    Posted 03-31-2023 09:22

    Tyrel,

    Apologies I should have been 100% clear. As Rapid 7 stated the network stack is different on Windows so the vulnerabilites do not affect Windows.  However the code changes we made to prevent the vulnerabilites were also made in the Windows version of UniVerse and UniData.  So it would seem prudent for Windows users to also upgrade and that is what we are recommending customers to do..

    Thanks,



    ------------------------------
    Jonathan Smith
    UniData ATS
    Rocket Support
    ------------------------------



  • 18.  RE: UniData/UniVerse Vulnerabilities Discovered by 3rd Party Researcher -Rocket Software's Security Commitment

    PARTNER
    Posted 03-31-2023 09:58

    Jonathan,

    Thanks for the clarification.  I don't disagree with the recommendation, but clients... 

    At any rate, the "must do" in order to deal with the vulnerability is entirely aimed at UNIX/Linux installations, while the "recommendation" (a best practice really) is a general statement aimed at all installations not already at these release levels.  From my point of view, the recommendation is pretty obvious as a general statement, but it doesn't really help me figure out how many cats I need to herd right now and with what urgency :-).

    As I indicated, I appreciate the clarification; I really do.  Thank you.



    ------------------------------
    Tyrel Marak
    Technical Support Manager
    Aptron Corporation
    Florham Park NJ US
    ------------------------------