Fortra fixes critical FileCatalyst Workflow hardcoded password issue
ID: 67c672ee-b4a7-5e82-ad7d-bb1c2ae88b82
STIX ID: report--67c672ee-b4a7-5e82-ad7d-bb1c2ae88b82
Feed Name: Bleeping Computer
Threat Score
Fortra warns of CVE-2024-6633: a critical (CVSS 9.8) hardcoded password in FileCatalyst Workflow's bundled HSQLDB ('GOSENSGO613') that is remotely accessible (TCP/4406) and can allow attackers to read sensitive data and create admin users; Tenable discovered the issue and Fortra advises upgrading to 5.1.7+ since HSQLDB is deprecated and no mitigations or workarounds exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
