Rocket Software maintains a focused portfolio of legacy enterprise data and application modernization platforms, particularly its UniData and Universe database products, which serve as the backbone for mission-critical business systems across financial services, telecommunications, and government sectors. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the memory-safety and authentication demands of aging middleware and database engines that often sit in privileged network positions. The exposure recurs through classic buffer overflows, out-of-bounds writes, improper authentication mechanisms, and path-traversal weaknesses that are characteristic of systems maintained across decades of legacy codebases with persistent backward-compatibility constraints. Defenders should prioritize patching for these products where they remain internet-accessible or in sensitive data-handling roles, as remediation timelines for mature enterprise platforms often lag discovery; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rocketsoftware over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3914HIGH Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) create arbitrary files via a .. (dot | Aug 7, 2014 | 10.0 | 81 | NO | YES |
CVE-2023-28503CRITICAL Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, | Mar 29, 2023 | 9.8 | 75 | NO | YES |
CVE-2023-28502CRITICAL Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "u | Mar 29, 2023 | 9.8 | 74 | NO | YES |
CVE-2025-27225HIGH TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive interna | Oct 27, 2025 | 7.5 | 49 | NO | YES |
CVE-2025-27222HIGH TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this e | Oct 27, 2025 | 8.6 | 42 | NO | YES |
CVE-2025-27223HIGH TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the applica | Oct 27, 2025 | 7.5 | 41 | NO | YES |
CVE-2025-32355HIGH Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs | Feb 17, 2026 | 7.3 | 37 | NO | YES |
CVE-2022-25026HIGH A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP re | Jan 12, 2023 | 7.5 | 37 | NO | NO |
CVE-2025-59793CRITICAL Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the applicati | Feb 17, 2026 | 9.9 | 32 | NO | NO |
CVE-2021-45024CRITICAL ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE). | Jun 17, 2022 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rocketsoftware.
Media articles that mention a CVE ID that affects a product developed by Rocketsoftware — matched by CVE ID, not by vendor name.