Inheriting Risk. Clearing 49 Security Vulnerabilities from a Legacy Service

Legacy Software

When a regulated organisation transferred a business-critical service from its incumbent supplier to Catapult, the handover came with more than code. A structured onboarding audit revealed 49 live security vulnerabilities, 58 out-of-date dependencies and an infrastructure estate that had drifted years behind. Catapult brought the whole stack up to date in a single, co-ordinated programme.

49 

Vulnerabilities eliminated 

17 

High or critical risks closed 

58 

Dependencies brought current 

THE CHALLENGE

You cannot maintain what you have not measured

Taking on a service you did not build is an act of inherited risk. Before committing to any maintenance obligation, Catapult ran a full onboarding audit across the UI, API, infrastructure, security posture and supporting documentation, establishing a baseline of exactly what had been handed over.

The audit found a service carrying significant, unmanaged security debt. Vulnerability scans across third-party dependencies identified 49 live issues, 17 of them rated high or critical, including server-side request forgery, command injection, prototype pollution and multiple cross-site scripting vectors. Alongside these sat 58 dependencies requiring version updates, 34 of them major version jumps, plus an operating system estate two releases behind current.

Critically, the components were interdependent. Upgrading any one in isolation risked breaking the others, which meant routine patching could not safely begin at all until the backlog was cleared.

Key blockers included:

  • 49 open vulnerabilities across the front end and API, 17 rated high or critical
  • 58 dependencies out of date, including 34 major version upgrades
  • Application servers running an operating system two major releases behind
  • No automated code or dependency scanning in place, so new vulnerabilities went undetected
  • Cross-dependencies between components that made incremental patching unsafe
  • Sparse documentation and around 7% test coverage, leaving little safety net for change
Rocket software case study

THE SOLUTION

Clear the decks, then keep them clear

Catapult’s recommendation was deliberately unglamorous. Rather than patch selectively around the risk, the team proposed clearing the entire backlog in one co-ordinated pass, then sustaining currency through contracted business-as-usual maintenance. A one-off remediation is a cost. A maintained baseline is an asset.

The audit also did the reverse job where the evidence supported it. The platform’s database was reported as running a version eleven years old, and was initially scoped for a costly major upgrade. Investigation established it was in fact fully patched and current, and the work was removed from scope, saving the client both budget and unnecessary change risk.

Key interventions included:

  • Full dependency remediation across the front end and API, clearing every outstanding major version update and known vulnerability in a single co-ordinated programme
  • Operating system upgrade across the application server estate, bringing platform-level patching back into support
  • Removal of redundant proxy and load balancer virtual machines identified as superseded by native cloud gateway services
  • Verification of the database version against actual patch state, removing an unnecessary major upgrade from scope
  • A staged approach that surfaced hidden compatibility issues early, with any component lacking a viable upgrade path escalated rather than forced
  • Transition into contracted BAU maintenance, so currency is held by routine rather than recovered by project
rocket software case study

THE RESULTS

From unmaintainable to routinely maintained

The remediation moved the service from a position where patching was impossible to one where it is business as usual. With the backlog cleared, staying current becomes an incremental, low-risk activity rather than a periodic crisis. 

  • 49 known vulnerabilities eliminated, including all 17 high and critical severity issues
  • 58 dependencies brought to current supported versions across both application layers
  • Application server operating systems returned to full vendor support and active patching
  • Redundant infrastructure removed, reducing both attack surface and running cost
  • Unnecessary database upgrade avoided through evidence-based scoping
  • Routine security patching unblocked and now delivered under ongoing maintenance
  • A documented security baseline established, aligned to Catapult’s ISO 27001 certified management system

Legacy modernisation is often sold as a transformation story. Just as often, the real value is quieter – removing the reasons a team cannot do the basics, so the basics can happen every month without drama.

Legacy Software

Don't miss these...