The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB.
The HSQLDB database included with FileCatalyst Workflow has default login credentials that were published in the manufacturer's documentation. Any attacker with network access to the HSQLDB port can use these known credentials to authenticate without any additional knowledge or tools. The issue affects installations where the administrator has not configured an alternative database according to manufacturer recommendations — HSQLDB is intended only as a convenience for the installation process and should not be used in a production environment.
An attacker with network access to the HSQLDB instance can gain full control over the application database, leading to violation of data confidentiality, modification of data, or complete disruption of the FileCatalyst Workflow system.
An immediate migration from the default HSQLDB database to an alternative database recommended by the manufacturer should be performed. Until migration is complete, network access to the HSQLDB port should be blocked using a firewall or ACL rules, restricting it to trusted hosts only. Detailed instructions are available in the manufacturer's security guide: https://www.fortra.com/security/advisories/product-security/fi-2024-011
Fortra FileCatalyst Workflow — installations using the default HSQLDB database that have not been configured to use an alternative database according to manufacturer recommendations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFortra Filecatalyst Workflow
APPFortra5.0.4 – 5.1.7 (excl.)
Related vulnerabilities
SQL Injection w Fortra FileCatalyst Workflow umożliwia modyfikację danych
Path traversal w Fortra FileCatalyst Workflow umożliwiający RCE przez web shell
A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to p...
Deserialization i command injection w Fortra GoAnywhere MFT (License Servlet)
Command injection w Fortra Core Privileged Access Manager (BoKS) — boks_autoregisterd