QID 731260

Date Published: 2024-03-18

QID 731260: Fortra FileCatalyst WorkFlow Remote Code Execution (RCE) Vulnerability (Intrusive Check)

A critical security vulnerability, designated as CVE-2024-25153, has been identified in Fortra FileCatalyst Workflow. This vulnerability allows remote attackers to execute arbitrary code on the targeted web server without requiring authentication. Specifically, the vulnerability enables an attacker to upload malicious files to the server and traverse directories, leading to Remote Code Execution (RCE).

Affected Versions:
Fortra FileCatalyst Workflow 5.x versions prior to 5.1.6 Build 114.

Note: A Fortra FileCatalyst WorkFlow instance is only exploitable if an anonymous user has access to upload files.

QID Detection Logic (Unauthenticated):
This is an intrusive detection. This QID tries to upload a static JSP file '731260.jsp' containing a static text 'File Generated By QID 731260', as an anonymous user. The '731260.jsp' file can be accessed by sending a HTTP GET request to the '/workflow/qualystest/731260.jsp' endpoint. A target is flagged as vulnerable if Qualys Scanner is able to upload 731260.jsp file to the FileCatalyst WorkFlow server. Please note that this QID does not check the version of FileCatalyst WorkFlow running on the target.

Exploitation of this vulnerability may allow an unauthenticated remote attacker to upload malicious JSP files to the server, leading to arbitrary code execution and complete system compromise.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    To mitigate the risk posed by this vulnerability, users and administrators are strongly advised to update their Fortra FileCatalyst Workflow installations to version 5.1.6 Build 114 or later. For more information, please refer to the Fortra Security Advisory (FI-2024-002)

    Vendor References

    CVEs related to QID 731260

    Software Advisories
    Advisory ID Software Component Link
    FI-2024-002 URL Logo www.fortra.com/security/advisory/fi-2024-002

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report