Rocketsoftware Rocketsoftware

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Rocketsoftware product.

RSS Feeds for Rocketsoftware security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Rocketsoftware products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Rocketsoftware Sorted by Most Security Vulnerabilities since 2018

Rocketsoftware Unidata9 vulnerabilities

Rocketsoftware Universe9 vulnerabilities

Rocketsoftware Ags Zena3 vulnerabilities

Rocketsoftware Trufusion1 vulnerability

Rocketsoftware Zena1 vulnerability

By the Year

In 2026 there have been 0 vulnerabilities in Rocketsoftware. Last year, in 2025 Rocketsoftware had 1 security vulnerability published. Right now, Rocketsoftware is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 1 0.00
2024 0 0.00
2023 11 8.90
2022 4 8.30

It may take a day or so for new Rocketsoftware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Rocketsoftware Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2024-45955 Jul 30, 2025
Rocket Zena 4.4.1.26 SQLi in filter param Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
Zena
CVE-2023-28508 Mar 29, 2023
Heap Overflow in Rocket UniData <8.2.4 Build 3003 & UniVerse <11.3.5/12.2.1 Crash Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.
Unidata
Universe
CVE-2023-28507 Mar 29, 2023
Rocket UniData/UniVerse Prior 8.2.4 Memory Exhaustion via Decompression Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.
Unidata
Universe
CVE-2023-28506 Mar 29, 2023
Rocket Software UniData<8.2.4 & UniVerse<11.3.5 Buffer Overflow Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.
Unidata
Universe
CVE-2023-28505 Mar 29, 2023
UniData/UniVerse Buffer Overflow in API Function (pre-8.2.4/pre-11.3.5) Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.
Unidata
Universe
CVE-2023-28504 Mar 29, 2023
Stack overrun in Rocket UniData<8.2.4 build3003 / UniVerse<11.3.5/12.2.1 RCE as root Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.
Unidata
Universe
CVE-2023-28503 Mar 29, 2023
Auth Bypass in Rocket UniData<8.2.4, UniVerse<11.3.5 via Custom User Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.
Unidata
Universe
CVE-2023-28509 Mar 29, 2023
Weak packet-level encryption in Rocket UniData <=8.2.4 (CVE202328509) Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.
Unidata
Universe
CVE-2023-28502 Mar 29, 2023
UniData/UniVerse udadmin Stack Overflow RCE (<=8.2.4,<=11.3.5,<=12.2.1) Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.
Unidata
Universe
CVE-2023-28501 Mar 29, 2023
Rocket UniData/UniVerse <8.2.4 or <11.3.5 RCE via unirpcd buffer overflow Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.
Unidata
Universe
CVE-2022-25027 Jan 12, 2023
Auth Bypass via Forgotten Password in Rocket TRUfusion Portal v7.9.2.1 The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
Trufusion Enterprise
CVE-2022-25026 Jan 12, 2023
SSRF in Rocket TRUfusion Portal v7.9.2.1 via upDwModuleProxy A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.
Trufusion Enterprise
CVE-2022-36431 Dec 01, 2022
Arbitrary File Upload in Rocket TRUfusion Enterprise <7.9.6.1 (JSP) An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
Trufusion
CVE-2021-45026 Jun 17, 2022
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS). ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
Ags Zena
CVE-2021-45025 Jun 17, 2022
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie. ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.
Ags Zena
CVE-2021-45024 Jun 17, 2022
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE). ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
Ags Zena
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.