CVE-2025-27225

7.5

Rocket Software · TRUfusion Enterprise

TRUfusion Enterprise through 7.10.4.0 exposes an internal administrative portal endpoint to unauthenticated users, leading to the unauthorized disclosure of sensitive PII.

Executive summary

A critical information disclosure vulnerability in Rocket Software TRUfusion Enterprise allows unauthenticated remote attackers to access sensitive internal data and PII.

Vulnerability

The application incorrectly exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to the public internet. This allows unauthenticated users to access sensitive PII without requiring any valid credentials.

Business impact

The exposure of PII and internal configuration data poses a significant risk to data privacy and regulatory compliance. With a CVSS score of 7.5, this high severity flaw could result in severe reputational damage and potential legal consequences due to unauthorized data exfiltration.

Remediation

Immediate Action: Contact Rocket Software support immediately to obtain the latest security patches or configuration guidance to disable access to the vulnerable administrative endpoint.

Proactive Monitoring: Review web server access logs for any requests directed toward the internal_admin_contact_login.jsp file originating from external IP addresses.

Compensating Controls: Implement strict network access control lists or a Web Application Firewall (WAF) rule to block all external traffic attempting to access the /trufusionPortal/jsp/ directory.

Exploitation status

Public Exploit Available: Yes, a detection template for Nuclei exists.

Analyst recommendation

Given the high impact of PII disclosure and the availability of technical details for this flaw, organizations must treat this as a high priority. Administrators should restrict access to the affected JSP endpoint immediately to prevent unauthorized data access while awaiting official patch deployment from the vendor.

More Rocket Software CVEs

Sources