logo

Fortra Patches Critical RCE Vulnerability in FileCatalyst Transfer Tool

ID: 9b5cbdef-04f5-51b7-bba3-b4ba9e0d4498

STIX ID: report--9b5cbdef-04f5-51b7-bba3-b4ba9e0d4498

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-03-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Fortra disclosed and patched a critical (CVSS 9.8) directory traversal vulnerability (CVE-2024-25153) in FileCatalyst Workflow that can be abused via a specially crafted POST request to upload JSP web shells and achieve remote code execution; a public proof-of-concept was published and users are advised to apply the update (FileCatalyst Workflow v5.1.6 Build 114).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.