rocketsoftware records
24 published records for vendor rocketsoftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 12.5%
- Pre-auth RCE
- 8
- With a fix record
- 41.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-190 Integer Overflow or Wraparound1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-312 Cleartext Storage of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2014-3914Weaponized | Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to rocketsoftware · rocket servergraph · CWE-22 | Critical10.0 | — | 72.6% | Aug 7, 2014 |
58Plan | CVE-2023-28503Weaponized | Authentication bypass in UniRPC's udadmin servicerocketsoftware · unidata · CWE-798 | Critical9.8 | — | 62.1% | Mar 29, 2023 |
57Plan | CVE-2023-28502Weaponized | Stack buffer overflow in UniRPC's udadmin_server servicerocketsoftware · unidata · CWE-120 | Critical9.8 | — | 61.1% | Mar 29, 2023 |
41Plan | CVE-2014-3915No exploit | The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary corocketsoftware · rocket servergraph · CWE-94 | Critical10.0 | — | 3.1% | Jun 11, 2014 |
39Monitor | CVE-2023-28504No exploit | Stack buffer overflow in UniRPC library functionrocketsoftware · unidata · CWE-120 | Critical9.8 | — | 1.4% | Mar 29, 2023 |
39Monitor | CVE-2023-28501No exploit | Heap buffer overflow in unirpcdrocketsoftware · unidata · CWE-190 | Critical9.8 | — | 1.4% | Mar 29, 2023 |
39Monitor | CVE-2022-36431No exploit | An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary crocketsoftware · trufusion · CWE-434 | Critical9.8 | — | 1.2% | Dec 1, 2022 |
39Monitor | CVE-2021-45024No exploit | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (rocketsoftware · ags-zena · CWE-611 | Critical9.8 | — | 1.1% | Jun 17, 2022 |
39Monitor | CVE-2023-28507No exploit | Memory exhaustion in LZ4 decompression in UniRPC daemonrocketsoftware · unidata · CWE-400 | Critical9.8 | — | 0.9% | Mar 29, 2023 |
39Monitor | CVE-2025-27224No exploit | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files.rocketsoftware · trufusion enterprise · CWE-20 | Critical9.8 | — | 0.9% | Oct 27, 2025 |
37Monitor | CVE-2022-25026No exploit | A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on throcketsoftware · trufusion enterprise · CWE-918 | High7.5 | — | 24.4% | Jan 12, 2023 |
37Monitor | CVE-2025-59793No exploit | Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be ablerocketsoftware · trufusion enterprise · CWE-35 | Critical9.4 | — | 1.1% | Feb 17, 2026 |
36Monitor | CVE-2025-27225Proof of concept | TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users.rocketsoftware · trufusion enterprise · CWE-200 | High7.5 | — | 18.4% | Oct 27, 2025 |
35Monitor | CVE-2025-27222Proof of concept | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files.rocketsoftware · trufusion enterprise · CWE-22 | High8.6 | — | 2.0% | Oct 27, 2025 |
35Monitor | CVE-2023-28506No exploit | Stack buffer overflow in UniRPC servicerocketsoftware · unidata · CWE-120 | High8.8 | — | 0.9% | Mar 29, 2023 |
35Monitor | CVE-2023-28508No exploit | Heap corruption in UniRPC servicerocketsoftware · unidata · CWE-120 | High8.8 | — | 0.9% | Mar 29, 2023 |
35Monitor | CVE-2023-28505No exploit | Buffer overflow in UniRPC library functionrocketsoftware · unidata · CWE-120 | High8.8 | — | 0.8% | Mar 29, 2023 |
31Monitor | CVE-2025-27223Proof of concept | TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPorrocketsoftware · trufusion enterprise · CWE-1004 | High7.5 | — | 2.2% | Oct 27, 2025 |
31Monitor | CVE-2025-32355Proof of concept | Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections.rocketsoftware · trufusion enterprise · CWE-918 | High7.9 | — | 1.2% | Feb 17, 2026 |
30Monitor | CVE-2022-25027No exploit | The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricrocketsoftware · trufusion enterprise · CWE-640 | High7.5 | — | 1.1% | Jan 12, 2023 |
30Monitor | CVE-2021-45025No exploit | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of rocketsoftware · ags-zena · CWE-312 | High7.5 | — | 0.6% | Jun 17, 2022 |
30Monitor | CVE-2023-28509No exploit | Weak encryption in UniRPC protocolrocketsoftware · unidata · CWE-327 | High7.5 | — | 0.3% | Mar 29, 2023 |
29Monitor | CVE-2024-45955No exploit | Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.rocketsoftware · zena · CWE-89 | High7.3 | — | 0.4% | Jul 30, 2025 |
24Monitor | CVE-2021-45026Proof of concept | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).rocketsoftware · ags-zena · CWE-79 | Medium6.1 | — | 1.2% | Jun 17, 2022 |
- CVE-2014-391462This week
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to
CriticalCVSS 10.0WeaponizedEPSS 73%rocketsoftware · rocket servergraphAug 7, 2014
- CVE-2023-2850358Plan
Authentication bypass in UniRPC's udadmin service
CriticalCVSS 9.8WeaponizedEPSS 62%rocketsoftware · unidataMar 29, 2023
- CVE-2023-2850257Plan
Stack buffer overflow in UniRPC's udadmin_server service
CriticalCVSS 9.8WeaponizedEPSS 61%rocketsoftware · unidataMar 29, 2023
- CVE-2014-391541Plan
The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary co
CriticalCVSS 10.0No exploitEPSS 3%rocketsoftware · rocket servergraphJun 11, 2014
- CVE-2023-2850439Monitor
Stack buffer overflow in UniRPC library function
CriticalCVSS 9.8No exploitEPSS 1%rocketsoftware · unidataMar 29, 2023
- CVE-2023-2850139Monitor
Heap buffer overflow in unirpcd
CriticalCVSS 9.8No exploitEPSS 1%rocketsoftware · unidataMar 29, 2023
- CVE-2022-3643139Monitor
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary c
CriticalCVSS 9.8No exploitEPSS 1%rocketsoftware · trufusionDec 1, 2022
- CVE-2021-4502439Monitor
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (
CriticalCVSS 9.8No exploitEPSS 1%rocketsoftware · ags-zenaJun 17, 2022
- CVE-2023-2850739Monitor
Memory exhaustion in LZ4 decompression in UniRPC daemon
CriticalCVSS 9.8No exploitEPSS 1%rocketsoftware · unidataMar 29, 2023
- CVE-2025-2722439Monitor
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files.
CriticalCVSS 9.8No exploitEPSS 1%rocketsoftware · trufusion enterpriseOct 27, 2025
- CVE-2022-2502637Monitor
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on th
HighCVSS 7.5No exploitEPSS 24%rocketsoftware · trufusion enterpriseJan 12, 2023
- CVE-2025-5979337Monitor
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able
CriticalCVSS 9.4No exploitEPSS 1%rocketsoftware · trufusion enterpriseFeb 17, 2026
- CVE-2025-2722536Monitor
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users.
HighCVSS 7.5Proof of conceptEPSS 18%rocketsoftware · trufusion enterpriseOct 27, 2025
- CVE-2025-2722235Monitor
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files.
HighCVSS 8.6Proof of conceptEPSS 2%rocketsoftware · trufusion enterpriseOct 27, 2025
- CVE-2023-2850635Monitor
Stack buffer overflow in UniRPC service
HighCVSS 8.8No exploitEPSS 1%rocketsoftware · unidataMar 29, 2023
- CVE-2023-2850835Monitor
Heap corruption in UniRPC service
HighCVSS 8.8No exploitEPSS 1%rocketsoftware · unidataMar 29, 2023
- CVE-2023-2850535Monitor
Buffer overflow in UniRPC library function
HighCVSS 8.8No exploitEPSS 1%rocketsoftware · unidataMar 29, 2023
- CVE-2025-2722331Monitor
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPor
HighCVSS 7.5Proof of conceptEPSS 2%rocketsoftware · trufusion enterpriseOct 27, 2025
- CVE-2025-3235531Monitor
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections.
HighCVSS 7.9Proof of conceptEPSS 1%rocketsoftware · trufusion enterpriseFeb 17, 2026
- CVE-2022-2502730Monitor
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restric
HighCVSS 7.5No exploitEPSS 1%rocketsoftware · trufusion enterpriseJan 12, 2023
- CVE-2021-4502530Monitor
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of
HighCVSS 7.5No exploitEPSS 1%rocketsoftware · ags-zenaJun 17, 2022
- CVE-2023-2850930Monitor
Weak encryption in UniRPC protocol
HighCVSS 7.5No exploitEPSS 0%rocketsoftware · unidataMar 29, 2023
- CVE-2024-4595529Monitor
Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
HighCVSS 7.3No exploitEPSS 0%rocketsoftware · zenaJul 30, 2025
- CVE-2021-4502624Monitor
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
MediumCVSS 6.1Proof of conceptEPSS 1%rocketsoftware · ags-zenaJun 17, 2022