TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.
References
| Link | Resource |
|---|---|
| https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27223.txt | Third Party Advisory |
| https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/ | Exploit Third Party Advisory |
| https://www.rocketsoftware.com/products/rocket-b2b-supply-chain-integration/rocket-trufusion-enterprise | Product |
Configurations
History
31 Oct 2025, 20:35
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27223.txt - Third Party Advisory | |
| References | () https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/ - Exploit, Third Party Advisory | |
| References | () https://www.rocketsoftware.com/products/rocket-b2b-supply-chain-integration/rocket-trufusion-enterprise - Product | |
| First Time |
Rocketsoftware
Rocketsoftware trufusion Enterprise |
|
| CPE | cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:* |
28 Oct 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-1004 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
27 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-27 17:15
Updated : 2025-10-31 20:35
NVD link : CVE-2025-27223
Mitre link : CVE-2025-27223
CVE.ORG link : CVE-2025-27223
JSON object : View
Products Affected
rocketsoftware
- trufusion_enterprise
CWE
CWE-1004
Sensitive Cookie Without 'HttpOnly' Flag
