Fortra disclosed a critical insecure-default vulnerability in FileCatalyst Workflow affecting version 5.1.6 Build 139 and earlier, tracked as CVE-2024-6633 with a CVSS 9.8 rating. The flaw exposes the product’s default HSQL database to remote attackers because default configuration credentials were publicly disclosed, allowing access to a service typically reachable on TCP port 4406.
Attackers who reach the database can create an administrative account in the web application and ultimately take full control of the vulnerable FileCatalyst Workflow instance. Fortra and CSIRT.SK advised organizations to upgrade to FileCatalyst Workflow 5.1.7 or later and to avoid using the default database in production by migrating the application to a supported external database platform.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that CVE-2024-6633 is a critical vulnerability with a CVSS score of 9.8 affecting Fortra FileCatalyst Workflow 5.1.6 Build 139 and earlier. The notice reiterated that attackers could use exposed default HSQL database credentials to create an administrative account and recommended upgrading to version 5.1.7 or later and avoiding the default database in production.
Fortra published advisory FI-2024-011 for an insecure default vulnerability in FileCatalyst Workflow 5.1.6 Build 139 and earlier. The issue allows remote attackers to access the default HSQL database and potentially gain full control of the web application.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.