rocketsoftware CVE Vulnerabilities & Metrics

Focus on rocketsoftware vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About rocketsoftware Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with rocketsoftware. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total rocketsoftware CVEs: 14
Earliest CVE date: 11 Jun 2014, 14:55 UTC
Latest CVE date: 29 Mar 2023, 21:15 UTC

Latest CVE reference: CVE-2023-28509

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical rocketsoftware CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.3

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 11
4.0-6.9 2
7.0-8.9 1
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS rocketsoftware CVEs

These are the five CVEs with the highest CVSS scores for rocketsoftware, sorted by severity first and recency.

All CVEs for rocketsoftware

CVE-2023-28509 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.

CVE-2023-28508 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.

CVE-2023-28507 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.

CVE-2023-28506 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.

CVE-2023-28505 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.

CVE-2023-28504 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.

CVE-2023-28503 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

CVE-2023-28502 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.

CVE-2023-28501 rocketsoftware vulnerability CVSS: 0 29 Mar 2023, 20:15 UTC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.

CVE-2022-25027 rocketsoftware vulnerability CVSS: 0 12 Jan 2023, 23:15 UTC

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

CVE-2022-25026 rocketsoftware vulnerability CVSS: 0 12 Jan 2023, 23:15 UTC

A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.

CVE-2021-45026 rocketsoftware vulnerability CVSS: 4.3 17 Jun 2022, 13:15 UTC

ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

CVE-2021-45025 rocketsoftware vulnerability CVSS: 5.0 17 Jun 2022, 13:15 UTC

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.

CVE-2021-45024 rocketsoftware vulnerability CVSS: 7.5 17 Jun 2022, 13:15 UTC

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

CVE-2014-3914 rocketsoftware vulnerability CVSS: 10.0 07 Aug 2014, 11:13 UTC

Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows remote attackers to (1) create arbitrary files via a .. (dot dot) in the query parameter in a writeDataFile action to the fileRequestor servlet, execute arbitrary files via a .. (dot dot) in the query parameter in a (2) run or (3) runClear action to the fileRequestor servlet, (4) read arbitrary files via a readDataFile action to the fileRequestor servlet, (5) execute arbitrary code via a save_server_groups action to the userRequest servlet, or (6) delete arbitrary files via a del action in the fileRequestServlet servlet.

CVE-2014-3915 rocketsoftware vulnerability CVSS: 10.0 11 Jun 2014, 14:55 UTC

The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands via a (1) auth, (2) auth_session, (3) auth_simple, (4) add, (5) add_flat, (6) remove, (7) set_pwd, (8) add_permissions, (9) revoke_permissions, (10) runAsync, or (11) tsmRequest command.