A serious security vulnerability affecting FileCatalyst Workflow that may be exploited by a remote attacker to obtain administrative access has been fixed by Fortra.
With a CVSS score of 9.8, the vulnerability—tracked as CVE-2024-6633—is caused by connecting to an HSQL database using a static password.
According to a vendor knowledge base article, the default credentials for setting up the HSQL database (HSQLDB) for FileCatalyst Workflow can be found, Fortra advised. If these credentials are misused, the software’s availability, confidentiality, or integrity may be jeopardized.
According to vendor guidelines, the HSQLDB has been deprecated and is solely offered to make installation easier read more about Fortra Issues Patch for High-Risk FileCatalyst Workflow Security Vulnerability.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
