Fortra has urgently released patches to address two critical SQL injection vulnerabilities in its FileCatalyst Workflow software, identified as CVE-2024-6632 and CVE-2024-6633. If exploited, these vulnerabilities could severely compromise the confidentiality, integrity, and availability of affected systems.
FileCatalyst Workflow, a prominent solution for transferring large files across networks, was found to have significant security flaws. The vulnerabilities were disclosed on August 27, 2024, following an investigation by cybersecurity firms Dynatrace and Tenable.
The flaws affect versions up to 5.1.6 Build 139, with the potential for unauthorized database modifications and information disclosure.
Free Webinar on Detecting & Blocking Supply Chain Attack -> Book your Spot
CVE-2024-6632: This vulnerability allows attackers to perform SQL injection attacks via a field accessible to super administrators. Such attacks can lead to unauthorized modifications of the database, posing a risk to data integrity and system availability.
The vulnerability was discovered during a routine security assessment by Dynatrace, which identified that user input was not adequately validated during the setup process, allowing for potential exploitation.
CVE-2024-6633: This issue involves the misuse of default credentials for the HSQL database used during installation. Although not intended for production use, systems that have not switched to an alternative database remain vulnerable. This flaw could lead to unauthorized access and data breaches.
Fortra has addressed these vulnerabilities in FileCatalyst Workflow version 5.1.7. Users are strongly advised to update their systems immediately to mitigate potential risks.
The company has emphasized the importance of following recommended configurations, particularly regarding database setup, to prevent unauthorized access.
Organizations using FileCatalyst Workflow should review their security protocols and ensure that all systems are updated to the latest version to protect against potential exploits.
Are You From SOC/DFIR Teams? - Try Advanced Malware and Phishing Analysis With ANY.RUN - 14 day free trial
APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…
The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…
Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…
A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…
Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…
SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…