Vulnerabilities > Fortra > Filecatalyst Workflow > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-27 CVE-2024-6633 Use of Hard-coded Credentials vulnerability in Fortra Filecatalyst Workflow
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article.
network
low complexity
fortra CWE-798
critical
9.8
2024-03-13 CVE-2024-25153 Exposure of Resource to Wrong Sphere vulnerability in Fortra Filecatalyst Workflow
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request.
network
low complexity
fortra CWE-668
critical
9.8