rocketsoftware kayıtları
rocketsoftware üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %12,5
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %41,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-190 Integer Overflow or Wraparound1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-312 Cleartext Storage of Sensitive Information1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2014-3914Silahlaştırılmış | Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to rocketsoftware · rocket servergraph · CWE-22 | Kritik10,0 | — | %72,6 | 7 Ağu 2014 |
58Planlayın | CVE-2023-28503Silahlaştırılmış | Authentication bypass in UniRPC's udadmin servicerocketsoftware · unidata · CWE-798 | Kritik9,8 | — | %62,1 | 29 Mar 2023 |
57Planlayın | CVE-2023-28502Silahlaştırılmış | Stack buffer overflow in UniRPC's udadmin_server servicerocketsoftware · unidata · CWE-120 | Kritik9,8 | — | %61,1 | 29 Mar 2023 |
41Planlayın | CVE-2014-3915İstismar yok | The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary corocketsoftware · rocket servergraph · CWE-94 | Kritik10,0 | — | %3,1 | 11 Haz 2014 |
39İzleyin | CVE-2023-28504İstismar yok | Stack buffer overflow in UniRPC library functionrocketsoftware · unidata · CWE-120 | Kritik9,8 | — | %1,4 | 29 Mar 2023 |
39İzleyin | CVE-2023-28501İstismar yok | Heap buffer overflow in unirpcdrocketsoftware · unidata · CWE-190 | Kritik9,8 | — | %1,4 | 29 Mar 2023 |
39İzleyin | CVE-2022-36431İstismar yok | An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary crocketsoftware · trufusion · CWE-434 | Kritik9,8 | — | %1,2 | 1 Ara 2022 |
39İzleyin | CVE-2021-45024İstismar yok | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (rocketsoftware · ags-zena · CWE-611 | Kritik9,8 | — | %1,1 | 17 Haz 2022 |
39İzleyin | CVE-2023-28507İstismar yok | Memory exhaustion in LZ4 decompression in UniRPC daemonrocketsoftware · unidata · CWE-400 | Kritik9,8 | — | %0,9 | 29 Mar 2023 |
39İzleyin | CVE-2025-27224İstismar yok | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files.rocketsoftware · trufusion enterprise · CWE-20 | Kritik9,8 | — | %0,9 | 27 Eki 2025 |
37İzleyin | CVE-2022-25026İstismar yok | A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on throcketsoftware · trufusion enterprise · CWE-918 | Yüksek7,5 | — | %24,4 | 12 Oca 2023 |
37İzleyin | CVE-2025-59793İstismar yok | Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be ablerocketsoftware · trufusion enterprise · CWE-35 | Kritik9,4 | — | %1,1 | 17 Şub 2026 |
36İzleyin | CVE-2025-27225Kavram kanıtı | TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users.rocketsoftware · trufusion enterprise · CWE-200 | Yüksek7,5 | — | %18,4 | 27 Eki 2025 |
35İzleyin | CVE-2025-27222Kavram kanıtı | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files.rocketsoftware · trufusion enterprise · CWE-22 | Yüksek8,6 | — | %2,0 | 27 Eki 2025 |
35İzleyin | CVE-2023-28506İstismar yok | Stack buffer overflow in UniRPC servicerocketsoftware · unidata · CWE-120 | Yüksek8,8 | — | %0,9 | 29 Mar 2023 |
35İzleyin | CVE-2023-28508İstismar yok | Heap corruption in UniRPC servicerocketsoftware · unidata · CWE-120 | Yüksek8,8 | — | %0,9 | 29 Mar 2023 |
35İzleyin | CVE-2023-28505İstismar yok | Buffer overflow in UniRPC library functionrocketsoftware · unidata · CWE-120 | Yüksek8,8 | — | %0,8 | 29 Mar 2023 |
31İzleyin | CVE-2025-27223Kavram kanıtı | TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPorrocketsoftware · trufusion enterprise · CWE-1004 | Yüksek7,5 | — | %2,2 | 27 Eki 2025 |
31İzleyin | CVE-2025-32355Kavram kanıtı | Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections.rocketsoftware · trufusion enterprise · CWE-918 | Yüksek7,9 | — | %1,2 | 17 Şub 2026 |
30İzleyin | CVE-2022-25027İstismar yok | The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricrocketsoftware · trufusion enterprise · CWE-640 | Yüksek7,5 | — | %1,1 | 12 Oca 2023 |
30İzleyin | CVE-2021-45025İstismar yok | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of rocketsoftware · ags-zena · CWE-312 | Yüksek7,5 | — | %0,6 | 17 Haz 2022 |
30İzleyin | CVE-2023-28509İstismar yok | Weak encryption in UniRPC protocolrocketsoftware · unidata · CWE-327 | Yüksek7,5 | — | %0,3 | 29 Mar 2023 |
29İzleyin | CVE-2024-45955İstismar yok | Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.rocketsoftware · zena · CWE-89 | Yüksek7,3 | — | %0,4 | 30 Tem 2025 |
24İzleyin | CVE-2021-45026Kavram kanıtı | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).rocketsoftware · ags-zena · CWE-79 | Orta6,1 | — | %1,2 | 17 Haz 2022 |
- CVE-2014-391462Bu hafta
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to
KritikCVSS 10,0SilahlaştırılmışEPSS %73rocketsoftware · rocket servergraph7 Ağu 2014
- CVE-2023-2850358Planlayın
Authentication bypass in UniRPC's udadmin service
KritikCVSS 9,8SilahlaştırılmışEPSS %62rocketsoftware · unidata29 Mar 2023
- CVE-2023-2850257Planlayın
Stack buffer overflow in UniRPC's udadmin_server service
KritikCVSS 9,8SilahlaştırılmışEPSS %61rocketsoftware · unidata29 Mar 2023
- CVE-2014-391541Planlayın
The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary co
KritikCVSS 10,0İstismar yokEPSS %3rocketsoftware · rocket servergraph11 Haz 2014
- CVE-2023-2850439İzleyin
Stack buffer overflow in UniRPC library function
KritikCVSS 9,8İstismar yokEPSS %1rocketsoftware · unidata29 Mar 2023
- CVE-2023-2850139İzleyin
Heap buffer overflow in unirpcd
KritikCVSS 9,8İstismar yokEPSS %1rocketsoftware · unidata29 Mar 2023
- CVE-2022-3643139İzleyin
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary c
KritikCVSS 9,8İstismar yokEPSS %1rocketsoftware · trufusion1 Ara 2022
- CVE-2021-4502439İzleyin
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (
KritikCVSS 9,8İstismar yokEPSS %1rocketsoftware · ags-zena17 Haz 2022
- CVE-2023-2850739İzleyin
Memory exhaustion in LZ4 decompression in UniRPC daemon
KritikCVSS 9,8İstismar yokEPSS %1rocketsoftware · unidata29 Mar 2023
- CVE-2025-2722439İzleyin
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files.
KritikCVSS 9,8İstismar yokEPSS %1rocketsoftware · trufusion enterprise27 Eki 2025
- CVE-2022-2502637İzleyin
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on th
YüksekCVSS 7,5İstismar yokEPSS %24rocketsoftware · trufusion enterprise12 Oca 2023
- CVE-2025-5979337İzleyin
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able
KritikCVSS 9,4İstismar yokEPSS %1rocketsoftware · trufusion enterprise17 Şub 2026
- CVE-2025-2722536İzleyin
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users.
YüksekCVSS 7,5Kavram kanıtıEPSS %18rocketsoftware · trufusion enterprise27 Eki 2025
- CVE-2025-2722235İzleyin
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files.
YüksekCVSS 8,6Kavram kanıtıEPSS %2rocketsoftware · trufusion enterprise27 Eki 2025
- CVE-2023-2850635İzleyin
Stack buffer overflow in UniRPC service
YüksekCVSS 8,8İstismar yokEPSS %1rocketsoftware · unidata29 Mar 2023
- CVE-2023-2850835İzleyin
Heap corruption in UniRPC service
YüksekCVSS 8,8İstismar yokEPSS %1rocketsoftware · unidata29 Mar 2023
- CVE-2023-2850535İzleyin
Buffer overflow in UniRPC library function
YüksekCVSS 8,8İstismar yokEPSS %1rocketsoftware · unidata29 Mar 2023
- CVE-2025-2722331İzleyin
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPor
YüksekCVSS 7,5Kavram kanıtıEPSS %2rocketsoftware · trufusion enterprise27 Eki 2025
- CVE-2025-3235531İzleyin
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections.
YüksekCVSS 7,9Kavram kanıtıEPSS %1rocketsoftware · trufusion enterprise17 Şub 2026
- CVE-2022-2502730İzleyin
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restric
YüksekCVSS 7,5İstismar yokEPSS %1rocketsoftware · trufusion enterprise12 Oca 2023
- CVE-2021-4502530İzleyin
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of
YüksekCVSS 7,5İstismar yokEPSS %1rocketsoftware · ags-zena17 Haz 2022
- CVE-2023-2850930İzleyin
Weak encryption in UniRPC protocol
YüksekCVSS 7,5İstismar yokEPSS %0rocketsoftware · unidata29 Mar 2023
- CVE-2024-4595529İzleyin
Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
YüksekCVSS 7,3İstismar yokEPSS %0rocketsoftware · zena30 Tem 2025
- CVE-2021-4502624İzleyin
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
OrtaCVSS 6,1Kavram kanıtıEPSS %1rocketsoftware · ags-zena17 Haz 2022