Vulnerability

Critical SQL Injection Vulnerability Discovered in Fortra FileCatalyst Workflow

Fortra has urgently released patches to address two critical SQL injection vulnerabilities in its FileCatalyst Workflow software, identified as CVE-2024-6632 and CVE-2024-6633. If exploited, these vulnerabilities could severely compromise the confidentiality, integrity, and availability of affected systems.

FileCatalyst Workflow, a prominent solution for transferring large files across networks, was found to have significant security flaws. The vulnerabilities were disclosed on August 27, 2024, following an investigation by cybersecurity firms Dynatrace and Tenable.

The flaws affect versions up to 5.1.6 Build 139, with the potential for unauthorized database modifications and information disclosure.

Free Webinar on Detecting & Blocking Supply Chain Attack -> Book your Spot

Details of the Vulnerabilities

CVE-2024-6632: This vulnerability allows attackers to perform SQL injection attacks via a field accessible to super administrators. Such attacks can lead to unauthorized modifications of the database, posing a risk to data integrity and system availability.

The vulnerability was discovered during a routine security assessment by Dynatrace, which identified that user input was not adequately validated during the setup process, allowing for potential exploitation.

CVE-2024-6633: This issue involves the misuse of default credentials for the HSQL database used during installation. Although not intended for production use, systems that have not switched to an alternative database remain vulnerable. This flaw could lead to unauthorized access and data breaches.

Fortra has addressed these vulnerabilities in FileCatalyst Workflow version 5.1.7. Users are strongly advised to update their systems immediately to mitigate potential risks.

The company has emphasized the importance of following recommended configurations, particularly regarding database setup, to prevent unauthorized access.

Organizations using FileCatalyst Workflow should review their security protocols and ensure that all systems are updated to the latest version to protect against potential exploits.

Are You From SOC/DFIR Teams? - Try Advanced Malware and Phishing Analysis With ANY.RUN - 14 day free trial

Guru Baran

Gurubaran is the Co-Founder and Editor-in-Chief of CyberSecurityNews.com, specializing in vulnerability analysis, malware research, ransomware, and computer forensics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

41 minutes ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

1 hour ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

1 hour ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

2 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

3 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

6 hours ago