CVE-2022-25026: SSRF
Published Jan 12, 2023
·Updated
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.
Affected Software
1 affected component
Rocketsoftware Trufusion Enterprise<7.9.5.1
Remediation
Event History
Jan 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-25026?
CVE-2022-25026 is classified as a critical severity vulnerability due to its potential for Server-Side Request Forgery (SSRF) attacks.
2
How do I fix CVE-2022-25026?
To fix CVE-2022-25026, upgrade Rocket TruFusion Portal to version 7.9.5.1 or later.
3
What are the potential impacts of CVE-2022-25026?
CVE-2022-25026 can allow remote attackers to access sensitive internal resources, which may lead to data breaches.
4
Who is affected by CVE-2022-25026?
Organizations using Rocket TruFusion Portal v7.9.2.1 through 7.9.5.0 are affected by CVE-2022-25026.
5
What type of vulnerability is CVE-2022-25026?
CVE-2022-25026 is a Server-Side Request Forgery (SSRF) vulnerability.