Authentication Vulnerability in TRUfusion Enterprise by Rocket Software
CVE-2025-27223

7.5HIGH

Key Information:

Vendor
CVE Published:
27 October 2025

What is CVE-2025-27223?

The TRUfusion Enterprise application through version 7.10.4.0 inadvertently exposes a sensitive authentication mechanism. By utilizing an encrypted COOKIEID for authentication, the application fails to properly secure this cookie due to the use of a static key for its encryption. This flaw enables an attacker to forge valid cookies, potentially allowing unauthorized access to sensitive internal data and endpoints like /trufusionPortal/getProjectList. Proper encryption practices and key management must be implemented to safeguard against such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.