CVE-2025-27225
7.5Rocket Software · TRUfusion Enterprise
TRUfusion Enterprise through 7.10.4.0 exposes an internal administrative portal endpoint to unauthenticated users, leading to the unauthorized disclosure of sensitive PII.
Executive summary
A critical information disclosure vulnerability in Rocket Software TRUfusion Enterprise allows unauthenticated remote attackers to access sensitive internal data and PII.
Vulnerability
The application incorrectly exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to the public internet. This allows unauthenticated users to access sensitive PII without requiring any valid credentials.
Business impact
The exposure of PII and internal configuration data poses a significant risk to data privacy and regulatory compliance. With a CVSS score of 7.5, this high severity flaw could result in severe reputational damage and potential legal consequences due to unauthorized data exfiltration.
Remediation
Immediate Action: Contact Rocket Software support immediately to obtain the latest security patches or configuration guidance to disable access to the vulnerable administrative endpoint.
Proactive Monitoring: Review web server access logs for any requests directed toward the internal_admin_contact_login.jsp file originating from external IP addresses.
Compensating Controls: Implement strict network access control lists or a Web Application Firewall (WAF) rule to block all external traffic attempting to access the /trufusionPortal/jsp/ directory.
Exploitation status
Public Exploit Available: Yes, a detection template for Nuclei exists.
Analyst recommendation
Given the high impact of PII disclosure and the availability of technical details for this flaw, organizations must treat this as a high priority. Administrators should restrict access to the affected JSP endpoint immediately to prevent unauthorized data access while awaiting official patch deployment from the vendor.