Записи rocketsoftware
24 опубликованных записей вендора rocketsoftware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 12,5 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 41,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-190 Integer Overflow or Wraparound1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-312 Cleartext Storage of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2014-3914Готовый эксплойт | Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to rocketsoftware · rocket servergraph · CWE-22 | Критическая10,0 | — | 72,6 % | 7 авг. 2014 г. |
58В плане | CVE-2023-28503Готовый эксплойт | Authentication bypass in UniRPC's udadmin servicerocketsoftware · unidata · CWE-798 | Критическая9,8 | — | 62,1 % | 29 мар. 2023 г. |
57В плане | CVE-2023-28502Готовый эксплойт | Stack buffer overflow in UniRPC's udadmin_server servicerocketsoftware · unidata · CWE-120 | Критическая9,8 | — | 61,1 % | 29 мар. 2023 г. |
41В плане | CVE-2014-3915Эксплойта нет | The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary corocketsoftware · rocket servergraph · CWE-94 | Критическая10,0 | — | 3,1 % | 11 июн. 2014 г. |
39Наблюдать | CVE-2023-28504Эксплойта нет | Stack buffer overflow in UniRPC library functionrocketsoftware · unidata · CWE-120 | Критическая9,8 | — | 1,4 % | 29 мар. 2023 г. |
39Наблюдать | CVE-2023-28501Эксплойта нет | Heap buffer overflow in unirpcdrocketsoftware · unidata · CWE-190 | Критическая9,8 | — | 1,4 % | 29 мар. 2023 г. |
39Наблюдать | CVE-2022-36431Эксплойта нет | An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary crocketsoftware · trufusion · CWE-434 | Критическая9,8 | — | 1,2 % | 1 дек. 2022 г. |
39Наблюдать | CVE-2021-45024Эксплойта нет | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (rocketsoftware · ags-zena · CWE-611 | Критическая9,8 | — | 1,1 % | 17 июн. 2022 г. |
39Наблюдать | CVE-2023-28507Эксплойта нет | Memory exhaustion in LZ4 decompression in UniRPC daemonrocketsoftware · unidata · CWE-400 | Критическая9,8 | — | 0,9 % | 29 мар. 2023 г. |
39Наблюдать | CVE-2025-27224Эксплойта нет | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files.rocketsoftware · trufusion enterprise · CWE-20 | Критическая9,8 | — | 0,9 % | 27 окт. 2025 г. |
37Наблюдать | CVE-2022-25026Эксплойта нет | A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on throcketsoftware · trufusion enterprise · CWE-918 | Высокая7,5 | — | 24,4 % | 12 янв. 2023 г. |
37Наблюдать | CVE-2025-59793Эксплойта нет | Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be ablerocketsoftware · trufusion enterprise · CWE-35 | Критическая9,4 | — | 1,1 % | 17 февр. 2026 г. |
36Наблюдать | CVE-2025-27225Proof of concept | TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users.rocketsoftware · trufusion enterprise · CWE-200 | Высокая7,5 | — | 18,4 % | 27 окт. 2025 г. |
35Наблюдать | CVE-2025-27222Proof of concept | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files.rocketsoftware · trufusion enterprise · CWE-22 | Высокая8,6 | — | 2,0 % | 27 окт. 2025 г. |
35Наблюдать | CVE-2023-28506Эксплойта нет | Stack buffer overflow in UniRPC servicerocketsoftware · unidata · CWE-120 | Высокая8,8 | — | 0,9 % | 29 мар. 2023 г. |
35Наблюдать | CVE-2023-28508Эксплойта нет | Heap corruption in UniRPC servicerocketsoftware · unidata · CWE-120 | Высокая8,8 | — | 0,9 % | 29 мар. 2023 г. |
35Наблюдать | CVE-2023-28505Эксплойта нет | Buffer overflow in UniRPC library functionrocketsoftware · unidata · CWE-120 | Высокая8,8 | — | 0,8 % | 29 мар. 2023 г. |
31Наблюдать | CVE-2025-27223Proof of concept | TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPorrocketsoftware · trufusion enterprise · CWE-1004 | Высокая7,5 | — | 2,2 % | 27 окт. 2025 г. |
31Наблюдать | CVE-2025-32355Proof of concept | Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections.rocketsoftware · trufusion enterprise · CWE-918 | Высокая7,9 | — | 1,2 % | 17 февр. 2026 г. |
30Наблюдать | CVE-2022-25027Эксплойта нет | The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricrocketsoftware · trufusion enterprise · CWE-640 | Высокая7,5 | — | 1,1 % | 12 янв. 2023 г. |
30Наблюдать | CVE-2021-45025Эксплойта нет | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of rocketsoftware · ags-zena · CWE-312 | Высокая7,5 | — | 0,6 % | 17 июн. 2022 г. |
30Наблюдать | CVE-2023-28509Эксплойта нет | Weak encryption in UniRPC protocolrocketsoftware · unidata · CWE-327 | Высокая7,5 | — | 0,3 % | 29 мар. 2023 г. |
29Наблюдать | CVE-2024-45955Эксплойта нет | Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.rocketsoftware · zena · CWE-89 | Высокая7,3 | — | 0,4 % | 30 июл. 2025 г. |
24Наблюдать | CVE-2021-45026Proof of concept | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).rocketsoftware · ags-zena · CWE-79 | Средняя6,1 | — | 1,2 % | 17 июн. 2022 г. |
- CVE-2014-391462На этой неделе
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to
КритическаяCVSS 10,0Готовый эксплойтEPSS 73 %rocketsoftware · rocket servergraph7 авг. 2014 г.
- CVE-2023-2850358В плане
Authentication bypass in UniRPC's udadmin service
КритическаяCVSS 9,8Готовый эксплойтEPSS 62 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2023-2850257В плане
Stack buffer overflow in UniRPC's udadmin_server service
КритическаяCVSS 9,8Готовый эксплойтEPSS 61 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2014-391541В плане
The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary co
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %rocketsoftware · rocket servergraph11 июн. 2014 г.
- CVE-2023-2850439Наблюдать
Stack buffer overflow in UniRPC library function
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2023-2850139Наблюдать
Heap buffer overflow in unirpcd
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2022-3643139Наблюдать
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary c
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rocketsoftware · trufusion1 дек. 2022 г.
- CVE-2021-4502439Наблюдать
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rocketsoftware · ags-zena17 июн. 2022 г.
- CVE-2023-2850739Наблюдать
Memory exhaustion in LZ4 decompression in UniRPC daemon
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2025-2722439Наблюдать
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rocketsoftware · trufusion enterprise27 окт. 2025 г.
- CVE-2022-2502637Наблюдать
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on th
ВысокаяCVSS 7,5Эксплойта нетEPSS 24 %rocketsoftware · trufusion enterprise12 янв. 2023 г.
- CVE-2025-5979337Наблюдать
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %rocketsoftware · trufusion enterprise17 февр. 2026 г.
- CVE-2025-2722536Наблюдать
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users.
ВысокаяCVSS 7,5Proof of conceptEPSS 18 %rocketsoftware · trufusion enterprise27 окт. 2025 г.
- CVE-2025-2722235Наблюдать
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files.
ВысокаяCVSS 8,6Proof of conceptEPSS 2 %rocketsoftware · trufusion enterprise27 окт. 2025 г.
- CVE-2023-2850635Наблюдать
Stack buffer overflow in UniRPC service
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2023-2850835Наблюдать
Heap corruption in UniRPC service
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2023-2850535Наблюдать
Buffer overflow in UniRPC library function
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2025-2722331Наблюдать
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPor
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %rocketsoftware · trufusion enterprise27 окт. 2025 г.
- CVE-2025-3235531Наблюдать
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections.
ВысокаяCVSS 7,9Proof of conceptEPSS 1 %rocketsoftware · trufusion enterprise17 февр. 2026 г.
- CVE-2022-2502730Наблюдать
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restric
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rocketsoftware · trufusion enterprise12 янв. 2023 г.
- CVE-2021-4502530Наблюдать
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rocketsoftware · ags-zena17 июн. 2022 г.
- CVE-2023-2850930Наблюдать
Weak encryption in UniRPC protocol
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %rocketsoftware · unidata29 мар. 2023 г.
- CVE-2024-4595529Наблюдать
Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %rocketsoftware · zena30 июл. 2025 г.
- CVE-2021-4502624Наблюдать
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
СредняяCVSS 6,1Proof of conceptEPSS 1 %rocketsoftware · ags-zena17 июн. 2022 г.