Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Insecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)
Vulnerability Description
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
信息暴露
Vulnerability Title
FileCatalyst Workflow 安全漏洞
Vulnerability Description
FileCatalyst Workflow是FileCatalyst公司的一个基于浏览器的大文件传输解决方案。 FileCatalyst Workflow存在安全漏洞,该漏洞源于使用的默认凭据已发布在供应商知识库文章中。
CVSS Information
N/A
Vulnerability Type
N/A