CVE-2019-18465: Critical severity progress moveit transfer vulnerability
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18465?
CVE-2019-18465 is a vulnerability in In Progress MOVEit Transfer 11.1 before 11.1.3 that allows an attacker to sign in without full credentials via the SSH (SFTP) interface.
How severe is CVE-2019-18465?
CVE-2019-18465 has a severity rating of 9.8 (critical).
How does CVE-2019-18465 affect MOVEit Transfer?
CVE-2019-18465 affects MOVEit Transfer 11.1 before 11.1.3 if certain SSH (SFTP) configurations are used and if the MySQL database is being used.
Is there a fix for CVE-2019-18465?
Yes, the fix for CVE-2019-18465 is to update to MOVEit Transfer 11.1.3 or later.
Where can I find more information about CVE-2019-18465?
You can find more information about CVE-2019-18465 in the Ipswitch community article and the MOVEit Transfer release notes.