CVE Vulnerabilities

CVE-2023-36933

Improper Handling of Exceptional Conditions

Published: Jul 05, 2023 | Modified: Jul 12, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Moveit_transfer Progress * 2020.1.11 (excluding)
Moveit_transfer Progress 2021.0 (including) 2021.0.9 (excluding)
Moveit_transfer Progress 2021.1.0 (including) 2021.1.7 (excluding)
Moveit_transfer Progress 2022.0.0 (including) 2022.0.7 (excluding)
Moveit_transfer Progress 2022.1.0 (including) 2022.1.8 (excluding)
Moveit_transfer Progress 2023.0.0 (including) 2023.0.4 (excluding)

References