Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Trufusion Enterprise HIGH 7.3
CVE-2025-32355

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that a…

Fix: 7.10.5.0+
Fix from $1,950 2026-02-17
Trufusion Enterprise CRITICAL 9.9
CVE-2025-59793

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to uploa…

Fix: 7.10.5.0+
Fix from $2,300 2026-02-17
Trufusion Enterprise CRITICAL 9.8
CVE-2025-27224

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly saniti…

Fix: after 7.10.4.0
Fix from $2,300 2025-10-27
Trufusion Enterprise HIGH 7.5
CVE-2025-27225EPSS 17%

TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpo…

Fix: after 7.10.4.0
Fix from $1,950 2025-10-27
Trufusion Enterprise HIGH 8.6
CVE-2025-27222

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't proper…

Fix: after 7.10.4.0
Fix from $1,950 2025-10-27
Trufusion Enterprise HIGH 7.5
CVE-2025-27223

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getPr…

Fix: after 7.10.4.0
Fix from $1,950 2025-10-27
Zena HIGH 7.3
CVE-2024-45955

Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.

No fix yet
Fix from $1,950 2025-07-30
Unidata CRITICAL 9.8
CVE-2023-28502EPSS 61%

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-…

Fix: after 12.2.1
Fix from $2,300 2023-03-29
Unidata CRITICAL 9.8
CVE-2023-28503EPSS 62%

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authe…

Fix: after 12.2.1
Fix from $2,300 2023-03-29
Unidata CRITICAL 9.8
CVE-2023-28504

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-…

Fix: after 12.2.1
Fix from $2,300 2023-03-29
Unidata CRITICAL 9.8
CVE-2023-28507

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory…

Fix: after 12.2.1
Fix from $2,300 2023-03-29
Unidata HIGH 8.8
CVE-2023-28505

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer…

Fix: after 12.2.1
Fix from $1,950 2023-03-29
Unidata HIGH 8.8
CVE-2023-28506

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-…

Fix: after 12.2.1
Fix from $1,950 2023-03-29
Unidata HIGH 8.8
CVE-2023-28508

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-b…

Fix: after 12.2.1
Fix from $1,950 2023-03-29
Unidata HIGH 7.5
CVE-2023-28509

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption …

Fix: after 12.2.1
Fix from $1,950 2023-03-29
Unidata CRITICAL 9.8
CVE-2023-28501

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-b…

Fix: after 12.2.1
Fix from $2,300 2023-03-29
Trufusion Enterprise HIGH 7.5
CVE-2022-25026EPSS 24%

A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the interna…

Fix: 7.9.5.1+
Fix from $1,950 2023-01-12
Trufusion Enterprise HIGH 7.5
CVE-2022-25027

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages…

Fix: 7.9.5.1+
Fix from $1,950 2023-01-12
Trufusion CRITICAL 9.8
CVE-2022-36431

An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a…

Fix: 7.9.6.1+
Fix from $2,300 2022-12-01
Ags Zena CRITICAL 9.8
CVE-2021-45024

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

Mitigation only
Fix from $2,300 2022-06-17
Ags Zena HIGH 7.5
CVE-2021-45025

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive…

Mitigation only
Fix from $1,950 2022-06-17
Ags Zena MEDIUM 6.1
CVE-2021-45026

ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

Mitigation only
Fix from $1,600 2022-06-17
Rocket Servergraph HIGH 10.0
CVE-2014-3914EPSS 73%

Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) creat…

Mitigation only
Fix from $1,950 2014-08-07
Rocket Servergraph HIGH 10.0
CVE-2014-3915

The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands vi…

Mitigation only
Fix from $1,950 2014-06-11