First published: Wed Jul 05 2023(Updated: )
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress MOVEit Transfer | <2020.1.11 | |
Progress MOVEit Transfer | >=2021.0<2021.0.9 | |
Progress MOVEit Transfer | >=2021.1.0<2021.1.7 | |
Progress MOVEit Transfer | >=2022.0.0<2022.0.7 | |
Progress MOVEit Transfer | >=2022.1.0<2022.1.8 | |
Progress MOVEit Transfer | >=2023.0.0<2023.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36933 is a vulnerability in Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4) that allows an attacker to invoke a method resulting in an unhandled exception.
CVE-2023-36933 has a severity rating of 7.5 (high).
Progress MOVEit Transfer versions before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4) are affected by CVE-2023-36933.
An attacker can exploit CVE-2023-36933 by invoking a method that causes an unhandled exception in the MOVEit Transfer application.
Yes, you can find more information about CVE-2023-36933 at the following references: [1](https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023) [2](https://www.progress.com/moveit)