漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Insecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)
Vulnerability Description
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only included to facilitate installation, has been deprecated, and is not intended for production use per vendor guides. However, users who have not configured FileCatalyst Workflow to use an alternative database per recommendations are vulnerable to attack from any source that can reach the HSQLDB.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
信息暴露
Vulnerability Title
FileCatalyst Workflow 安全漏洞
Vulnerability Description
FileCatalyst Workflow是FileCatalyst公司的一个基于浏览器的大文件传输解决方案。 FileCatalyst Workflow存在安全漏洞,该漏洞源于使用的默认凭据已发布在供应商知识库文章中。
CVSS Information
N/A
Vulnerability Type
N/A