Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rocketsoftware

First CVE: Jun 11, 2014Active for: 12 yearsTotal CVEs: 24
64.1
VTI Score
TOP TARGET

Rocket Software maintains a focused portfolio of legacy enterprise data and application modernization platforms, particularly its UniData and Universe database products, which serve as the backbone for mission-critical business systems across financial services, telecommunications, and government sectors. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the memory-safety and authentication demands of aging middleware and database engines that often sit in privileged network positions. The exposure recurs through classic buffer overflows, out-of-bounds writes, improper authentication mechanisms, and path-traversal weaknesses that are characteristic of systems maintained across decades of legacy codebases with persistent backward-compatibility constraints. Defenders should prioritize patching for these products where they remain internet-accessible or in sensitive data-handling roles, as remediation timelines for mature enterprise platforms often lag discovery; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rocketsoftware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2014
12 years ago
Most Recent CVE
Feb 17, 2026
158 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-3914HIGH
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) create arbitrary files via a .. (dot
Aug 7, 201410.081NOYES
CVE-2023-28503CRITICAL
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability,
Mar 29, 20239.875NOYES
CVE-2023-28502CRITICAL
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "u
Mar 29, 20239.874NOYES
CVE-2025-27225HIGH
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive interna
Oct 27, 20257.549NOYES
CVE-2025-27222HIGH
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this e
Oct 27, 20258.642NOYES
CVE-2025-27223HIGH
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the applica
Oct 27, 20257.541NOYES
CVE-2025-32355HIGH
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs
Feb 17, 20267.337NOYES
CVE-2022-25026HIGH
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP re
Jan 12, 20237.537NONO
CVE-2025-59793CRITICAL
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the applicati
Feb 17, 20269.932NONO
CVE-2021-45024CRITICAL
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
Jun 17, 20229.832NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
58%
38%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (91.7%)
Unknown2 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (91.7%)
High0 (0.0%)
Unknown2 (8.3%)
User Interaction
None21 (87.5%)
Unknown2 (8.3%)
Required1 (4.2%)
Privileges Required
Low4 (16.7%)
High0 (0.0%)
None18 (75.0%)
Unknown2 (8.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
12.5% of CVEs· 98th percentile
Nuclei
4 CVEs
16.7% of CVEs· 97th percentile
ExploitDB
1 CVE
4.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rocketsoftware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rocketsoftware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rocketsoftware's Products

View all 2 CNAs →

Top CWEs