CVE-2025-27223
7.5Rocket Software · TRUfusion Enterprise
TRUfusion Enterprise uses a static key for cookie encryption, allowing unauthenticated attackers to forge cookies and access sensitive project information.
Executive summary
A critical authentication bypass vulnerability in Rocket Software TRUfusion Enterprise allows unauthenticated attackers to access sensitive internal data via forged session cookies.
Vulnerability
This vulnerability involves the use of a static cryptographic key to encrypt session cookies. An unauthenticated attacker can leverage this weakness to forge valid authentication cookies and bypass access controls on specific endpoints, such as the project list portal.
Business impact
The ability for an unauthenticated user to forge session cookies poses a significant risk to the confidentiality of sensitive supply chain data. Successful exploitation could lead to unauthorized access to internal project information, potentially resulting in intellectual property theft or business intelligence compromise. With a CVSS score of 7.5, this high severity flaw represents a clear and present danger to exposed instances.
Remediation
Immediate Action: Contact Rocket Software support immediately to obtain the latest security patches or configuration guidance to rotate the affected cryptographic keys.
Proactive Monitoring: Review web server and application access logs for unusual patterns, such as a high volume of requests to the /trufusionPortal/getProjectList endpoint originating from unexpected sources.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block suspicious cookie formats or unauthorized access patterns targeting the identified portal endpoints.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as attributed to the technical write-up provided by RCE Security and the researcher's advisory.
Analyst recommendation
Given the ease of exploitation and the potential for unauthorized data access, organizations running TRUfusion Enterprise must prioritize the remediation of this flaw. Administrators should verify their current version against the affected range and apply any available vendor updates immediately to prevent credential forgery and data exfiltration.