The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software.
The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-798 |
Tue, 27 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortra
Fortra filecatalyst Workflow |
|
| CPEs | cpe:2.3:a:fortra:filecatalyst_workflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortra
Fortra filecatalyst Workflow |
|
| Metrics |
ssvc
|
Tue, 27 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB. | |
| Title | Insecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier) | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Fortra
Published: 2024-08-27T14:11:24.527Z
Updated: 2025-08-29T20:21:54.534Z
Reserved: 2024-07-09T20:02:00.215Z
Link: CVE-2024-6633
Updated: 2024-08-27T14:44:04.467Z
Status : Modified
Published: 2024-08-27T15:15:17.513
Modified: 2025-08-29T21:15:35.107
Link: CVE-2024-6633
No data.