CRITICAL🇵🇱 Wersja polska

CVE-2024-6633

CVSS 9.8v3.1pub. 2024-08-27upd. 2025-08-29

The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB.

🤖 AI Analysis
How it works

The HSQLDB database included with FileCatalyst Workflow has default login credentials that were published in the manufacturer's documentation. Any attacker with network access to the HSQLDB port can use these known credentials to authenticate without any additional knowledge or tools. The issue affects installations where the administrator has not configured an alternative database according to manufacturer recommendations — HSQLDB is intended only as a convenience for the installation process and should not be used in a production environment.

Impact

An attacker with network access to the HSQLDB instance can gain full control over the application database, leading to violation of data confidentiality, modification of data, or complete disruption of the FileCatalyst Workflow system.

Mitigation & patch

An immediate migration from the default HSQLDB database to an alternative database recommended by the manufacturer should be performed. Until migration is complete, network access to the HSQLDB port should be blocked using a firewall or ACL rules, restricting it to trusted hosts only. Detailed instructions are available in the manufacturer's security guide: https://www.fortra.com/security/advisories/product-security/fi-2024-011

Who is affected

Fortra FileCatalyst Workflow — installations using the default HSQLDB database that have not been configured to use an alternative database according to manufacturer recommendations.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Fortra Filecatalyst Workflow

    APP
    Fortra
    5.0.4 – 5.1.7 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-5276CRITICAL9.8PL ✓same product

SQL Injection w Fortra FileCatalyst Workflow umożliwia modyfikację danych

CVE-2024-25153CRITICAL9.8PL ✓same product

Path traversal w Fortra FileCatalyst Workflow umożliwiający RCE przez web shell

CVE-2024-6632HIGH7.2same product

A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to p...

CVE-2025-10035CRITICAL10.0⚠ KEVPL ✓same vendor

Deserialization i command injection w Fortra GoAnywhere MFT (License Servlet)

CVE-2026-9862CRITICAL9.8PL ✓same vendor

Command injection w Fortra Core Privileged Access Manager (BoKS) — boks_autoregisterd