fortra CVE Vulnerabilities & Metrics

Focus on fortra vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About fortra Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with fortra. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total fortra CVEs: 9
Earliest CVE date: 06 Feb 2023, 20:15 UTC
Latest CVE date: 09 Oct 2024, 23:15 UTC

Latest CVE reference: CVE-2024-8264

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 6

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 200.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 200.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical fortra CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.0

Max CVSS: 0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS fortra CVEs

These are the five CVEs with the highest CVSS scores for fortra, sorted by severity first and recency.

All CVEs for fortra

CVE-2024-8264 fortra vulnerability CVSS: 0 09 Oct 2024, 23:15 UTC

Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.

CVE-2024-25157 fortra vulnerability CVSS: 0 14 Aug 2024, 15:15 UTC

An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.

CVE-2024-25156 fortra vulnerability CVSS: 0 14 Mar 2024, 14:15 UTC

A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.

CVE-2024-25155 fortra vulnerability CVSS: 0 13 Mar 2024, 15:15 UTC

In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script tag. 

CVE-2024-25154 fortra vulnerability CVSS: 0 13 Mar 2024, 15:15 UTC

Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.  

CVE-2024-25153 fortra vulnerability CVSS: 0 13 Mar 2024, 15:15 UTC

A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.

CVE-2024-0204 fortra vulnerability CVSS: 0 22 Jan 2024, 18:15 UTC

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

CVE-2023-6253 fortra vulnerability CVSS: 0 22 Nov 2023, 12:15 UTC

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

CVE-2023-0669 fortra vulnerability CVSS: 0 06 Feb 2023, 20:15 UTC

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.