The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB.
History

Fri, 30 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798

Tue, 27 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Fortra
Fortra filecatalyst Workflow
CPEs cpe:2.3:a:fortra:filecatalyst_workflow:*:*:*:*:*:*:*:*
Vendors & Products Fortra
Fortra filecatalyst Workflow
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 27 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Description The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB.
Title Insecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published: 2024-08-27T14:11:24.527Z

Updated: 2024-08-29T03:55:32.406Z

Reserved: 2024-07-09T20:02:00.215Z

Link: CVE-2024-6633

cve-icon Vulnrichment

Updated: 2024-08-27T14:44:04.467Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-27T15:15:17.513

Modified: 2024-08-30T14:11:45.287

Link: CVE-2024-6633

cve-icon Redhat

No data.