Fortra Releases Patch to Address High-Risk FileCatalyst Workflow Security Vulnerability

Published:

spot_img

FileCatalyst Workflow Security Vulnerability Patched by Fortra

A critical security flaw in FileCatalyst Workflow has been addressed by Fortra, preventing remote attackers from gaining administrative access. The vulnerability, known as CVE-2024-6633, scored a 9.8 on the CVSS scale and was caused by the use of a static password to connect to an HSQL database.

Fortra warned that default credentials for the HSQL database were published in a vendor knowledge base article, potentially compromising the software’s confidentiality, integrity, and availability. Cybersecurity company Tenable discovered the flaw, noting that the HSQLDB is remotely accessible on TCP port 4406 by default, allowing attackers to connect and perform malicious operations.

After responsible disclosure on July 2, 2024, Fortra released a patch for FileCatalyst Workflow version 5.1.7 and above. This patch also addressed a high-severity SQL injection flaw (CVE-2024-6632, CVSS score: 7.2) that allowed unauthorized modifications to the database during the setup process.

Robin Wyss, a researcher at Dynatrace, highlighted that user input during the setup process was not properly validated, enabling attackers to modify database queries and make unauthorized changes. As a result, users are advised to update their software to version 5.1.7 or later to protect against these vulnerabilities.

spot_img

Related articles

Recent articles

Dark Web Contest Awards $10,000 for Technical Writing on Vulnerability Exploitation

Dark Web Contest Awards $10,000 for Technical Writing on Vulnerability Exploitation In a notable shift within the underground cyber landscape, the TierOne forum has announced...

Kaspersky Report Reveals 1 Million Banking Accounts Compromised as E-Commerce Scams Surge to 85% of Financial Phishing in the Middle East

Kaspersky Report Reveals 1 Million Banking Accounts Compromised as E-Commerce Scams Surge to 85% of Financial Phishing in the Middle East In a significant shift...

The Strategic Framework Strengthening Security in Hospitality by 2026

The Strategic Framework Strengthening Security in Hospitality by 2026 The hospitality industry is evolving into a complex ecosystem where security plays a pivotal role in...

Hackers Exploit Kali Forms Vulnerability to Achieve Remote Code Execution on WordPress Sites

Hackers Exploit Kali Forms Vulnerability to Achieve Remote Code Execution on WordPress Sites A newly uncovered vulnerability in the Kali Forms plugin, a popular drag-and-drop...