Fortra Security Updates – 19 March 2024

Fortra has released security updates to address several vulnerabilities in multiple Fortra products.

The addressed vulnerabilities could allow the remote attacker to conduct crosssite scripting attacks, perform directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allow files to be uploaded outside of the intended ‘uploadtemp’ directory by sending specially crafted POST requests, or execute arbitrary code, and gain access to the affected product.

Sample of the addressed vulnerabilities:

Fortra FileCatalyst Directory Traversal Vulnerability (CVE-2024-25153):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

The affected products:

  • Fortra FileCatalyst Workflow 5.x before 5.1.6 Build 114.
  • Fortra GoAnywhere MFT prior to 7.4.2.
  • Fortra FileCatalyst Direct 3.x before 3.8.9.
Vulnerabilities
  • CVE-2024-25153
  • CVE-2024-25154
  • CVE-2024-25155
  • CVE-2024-25156
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Fortra Security Update

References