Fortra Releases Patch to Address High-Risk FileCatalyst Workflow Security Vulnerability

Published:

spot_img

FileCatalyst Workflow Security Vulnerability Patched by Fortra

A critical security flaw in FileCatalyst Workflow has been addressed by Fortra, preventing remote attackers from gaining administrative access. The vulnerability, known as CVE-2024-6633, scored a 9.8 on the CVSS scale and was caused by the use of a static password to connect to an HSQL database.

Fortra warned that default credentials for the HSQL database were published in a vendor knowledge base article, potentially compromising the software’s confidentiality, integrity, and availability. Cybersecurity company Tenable discovered the flaw, noting that the HSQLDB is remotely accessible on TCP port 4406 by default, allowing attackers to connect and perform malicious operations.

After responsible disclosure on July 2, 2024, Fortra released a patch for FileCatalyst Workflow version 5.1.7 and above. This patch also addressed a high-severity SQL injection flaw (CVE-2024-6632, CVSS score: 7.2) that allowed unauthorized modifications to the database during the setup process.

Robin Wyss, a researcher at Dynatrace, highlighted that user input during the setup process was not properly validated, enabling attackers to modify database queries and make unauthorized changes. As a result, users are advised to update their software to version 5.1.7 or later to protect against these vulnerabilities.

spot_img

Related articles

Recent articles

WhatsApp Launches Beta of Scam Alert Feature to Identify Suspicious Messages

WhatsApp has initiated a limited beta rollout of its Scam Alert feature, designed to identify suspicious messages from non-contacts using an on-device machine learning...

Ransomware Recovery Challenges: 34% of ANZ Organizations Still Opt to Pay Ransom Despite Uncertain Outcomes

Research published by Commvault reveals that 34% of organizations in Australia and New Zealand that experienced a ransomware attack opted to pay the ransom....

OpenAI Flags Astra Model for Critical Cybersecurity Risks, Halting Development

OpenAI has raised alarms regarding its forthcoming AI model, Astra, which may pose a ‘critical’ cybersecurity risk. This assessment has led the company to...

Redomiciling to Dubai does not exempt firms from MiCA obligations, warns Relm official

Insurance gaps in director liability, custody, and wallets often surface only after crypto firms relocate, warns Relm’s global distribution chief. Dubai has become a focal...