Skip to main content

Vendor/product archive

rocketsoftware / trufusion_enterprise CVEs

Beta · best-effort

8 CVEs tagged to rocketsoftware / trufusion_enterprise2 Critical, 6 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-32355

Published Feb 17, 2026

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59793

Published Feb 17, 2026

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the applicat…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27225

Published Oct 27, 2025

TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive intern…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27224

Published Oct 27, 2025

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27223

Published Oct 27, 2025

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the applic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27222

Published Oct 27, 2025

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25026

Published Jan 12, 2023

A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1