iTnews Asia
  • Home
  • News
  • Security

Progress Software moves on another MOVEit vulnerability

Progress Software moves on another MOVEit vulnerability

Irresponsible disclosure by third party.

By Richard Chirgwin on Jun 19, 2023 11:46AM

Progress Software’s ongoing MOVEit saga continued late last week, with the company moving to patch another security vulnerability in its managed file transfer software.

Advising that it had patched an SQLi bug designated CVE-2023-35708, Progress Software said the party that found the bug “did not follow normal industry standards”.

“Because it is common across the industry that reported vulnerabilities lead to increased attention from both malicious threat actors and cyber security researchers trying to uncover new vulnerabilities, we are working closely with our industry partners to take all appropriate steps to address any issues,” the company said.

NIST’s advisory said the bug “could allow an unauthenticated attacker to gain unauthorised access to MOVEit Transfer's database."

"An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content," NIST stated.

When it discovered the bug, Progress disabled HTTPs traffic on MOVEit Cloud, and asked customers “to take down their HTTP and HTTPs traffic to safeguard their environments”.

Progress said it has not seen any evidence that the new vulnerability was being exploited, and has updated a knowledge base article to tell customers how to apply the latest patch.

Problems with MOVEit first emerged early in June, with victims of the earlier bug including British Airways, the BBC, and several unnamed US government agencies.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
moveit progress software security

Related Articles

  • Sophos: Identity attacks have overtaken software flaws as entry point of ransomware
  • Strategies to mitigate against the real world impact of identity attacks
  • How can the Agentic AI workspace remain secure for APAC organisations?
  • AI-fuelled attacks forcing enterprises to rethink security architecture
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Singtel appoints new group CISO

Singtel appoints new group CISO

How severe will ransomware attacks become in 2026?

How severe will ransomware attacks become in 2026?

EU drops sovereignty requirements in cybersecurity certification scheme

EU drops sovereignty requirements in cybersecurity certification scheme

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.