Junglewise Threat Intelligence

CVE-2024-45955: Rocket Software Rocket Zena SQL injection in filter parameter

CVE-2024-45955 · Severity: high · CVSS 7.3 · Published 2025-07-30

Executive brief

Rocket Zena, a workload automation tool used to manage business processes and system events, is vulnerable to a security flaw that could allow unauthorized access to its underlying database. By exploiting this weakness, an attacker could potentially view, modify, or delete sensitive system data and logs. This could lead to operational disruptions or the exposure of confidential configuration information.

Technical details

An authenticated SQL injection vulnerability exists in Rocket Zena version 4.4.1.26. The flaw is located in the 'filter' parameter used across several search endpoints, including /scheduler/logs/search, /events/search, and /alerts/search. The application fails to properly sanitize user-supplied input, specifically failing to handle single quotes, which results in direct SQL error leakage and allows for error-based SQL injection. An attacker with standard user privileges can exploit this to retrieve sensitive information, such as database version banners and potentially full table contents. The vulnerability was addressed in version 4.4.2.50.

Affected products

  • Rocket Software Zena 4.4.1.26

Timeline

  • 2024-07-23: disclosed: Initial contact with vendor
  • 2024-08-08: patched: Vendor fixed the vulnerability in version 4.4.2.50
  • 2025-07-30: advisory: NVD publication date

References