logo

Fortra Releases Update on Critical Severity RCE Flaw

ID: cbe5ce95-24e5-5d4e-8f51-fc82d5591c2d

STIX ID: report--cbe5ce95-24e5-5d4e-8f51-fc82d5591c2d

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-03-19

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Fortra disclosed a critical directory-traversal vulnerability (CVE-2024-25153, CVSS 9.8) in FileCatalyst Workflow 5.x that allows unauthenticated attackers to upload files outside the intended directory and potentially deploy JSP web shells for remote code execution; Fortra advises upgrading to 5.1.6 Build 114 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.