Rocketsoftware
Rocketsoftware Trufusion Enterprise: vulnerabilidades y CVE
Rocketsoftware Trufusion Enterprise tiene 8 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses6
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-32355 | Alta (7.9) | 1.2% | — | 17 feb 2026 | Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the… |
| CVE-2025-59793 | Crítica (9.4) | 1.1% | — | 17 feb 2026 | Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the… |
| CVE-2025-27225 | Alta (7.5) | 18% | — | 27 oct 2025 | TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to… |
| CVE-2025-27224 | Crítica (9.8) | 0.87% | — | 27 oct 2025 | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal… |
| CVE-2025-27223 | Alta (7.5) | 2.2% | — | 27 oct 2025 | TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the… |
| CVE-2025-27222 | Alta (8.6) | 2.0% | — | 27 oct 2025 | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path… |
| CVE-2022-25027 | Alta (7.5) | 1.1% | — | 12 ene 2023 | The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?"… |
| CVE-2022-25026 | Alta (7.5) | 24% | — | 12 ene 2023 | A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to… |