Progress Vulnerabilities and Affected Products
Vulnerabilities associated with ws_ftp_server.
Products
Clear product- MOVEit Transfer22 vulnerabilities
- whatsup_gold21 vulnerabilities
- LoadMaster11 vulnerabilities
- telerik_reporting8 vulnerabilities
- ws_ftp_server6 vulnerabilities
- openedge5 vulnerabilities
- whatsupgold5 vulnerabilities
- ui_for_wpf4 vulnerabilities
- moveit_transfer3 vulnerabilities
- ShareFile Storage Zones Controller3 vulnerabilities
- sitefinity3 vulnerabilities
- WhatsUp Gold3 vulnerabilities
- DataDirect Connect for JDBC Autonomous REST Connector2 vulnerabilities
- DataDirect Connect for JDBC for Amazon Redshift2 vulnerabilities
- DataDirect Connect for JDBC for Apache Cassandra2 vulnerabilities
- DataDirect Connect for JDBC for Apache Impala2 vulnerabilities
- DataDirect Connect for JDBC for Apache SparkSQL2 vulnerabilities
- DataDirect Connect for JDBC for DB22 vulnerabilities
- DataDirect Connect for JDBC for Google Analytics 42 vulnerabilities
- DataDirect Connect for JDBC for Google BigQuery2 vulnerabilities
- DataDirect Connect for JDBC for Greenplum2 vulnerabilities
- DataDirect Connect for JDBC for Hive2 vulnerabilities
- DataDirect Connect for JDBC for Informix2 vulnerabilities
- DataDirect Connect for JDBC for Microsoft Dynamics 3652 vulnerabilities
- DataDirect Connect for JDBC for Microsoft Sharepoint2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-7745MEDIUM | Multi-Factor Authentication Bypass in Progress WS_FTP ServerIn WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only. | CVSS6.5v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7744MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP ServerIn WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal. An authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:) | CVSS6.5v3.1 | EPSS0.688% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-40049MEDIUM | WS_FTP Server Information Disclosure via Directory ListingIn WS_FTP Server version prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing. CWE-200Sep 27, 2023 | CVSS5.3v3.1 | EPSS0.747% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-40047HIGH | WS_FTP Server Stored Cross-Site Scripting VulnerabilityIn WS_FTP Server version prior to 8.8.2, a stored cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Management module. An attacker with administrative privileges could import a SSL certificate with malicious attributes containing cross-site scripting payloads. Once the cross-site scripting payload is successfully stored, an attacker could leverage this vulnerability to target WS_FTP Server admins with a specialized payload which results in the execution of malicious JavaScrip… CWE-79Sep 27, 2023 | CVSS8.3v3.1 | EPSS0.409% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-40045HIGH | WS_FTP Server Ad Hoc Transfer Module Reflected Cross-Site Scripting VulnerabilityIn WS_FTP Server versions prior to 8.7.4 and 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Ad Hoc Transfer module. An attacker could leverage this vulnerability to target WS_FTP Server users with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser. CWE-79Sep 27, 2023 | CVSS8.3v3.1 | EPSS0.895% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42657CRITICAL | WS_FTP Server Directory TraversalIn WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path. Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system. CWE-22Sep 27, 2023 | CVSS9.9v3.1 | EPSS17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |