CVE-2024-6633 is a critical vulnerability affecting Fortra FileCatalyst Workflow, stemming from publicly disclosed default credentials for its setup HSQL database. This flaw carries a CVSS score of 9.8 (CRITICAL), indicating it can be exploited remotely with low complexity, potentially leading to a complete compromise of confidentiality, integrity, and availability. While the HSQLDB is intended for installation and deprecated, unpatched systems are vulnerable to attack. There is no evidence of active exploitation, nor are public exploits available, but the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.4, < 5.1.7CPE matchmatch criteria | cpe:2.3:a:fortra:filecatalyst_workflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Fortra FileCatalyst Workflow Static HSQLDB Password
Aug 27, 2024Fortra FileCatalyst Workflow Static HSQLDB Password
Aug 27, 2024Fortra FileCatalyst Workflow Static HSQLDB Password
Aug 27, 2024