Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Fortra/
  3. Fortra DLP

Fortra DLP

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 26 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

DLP platform protecting sensitive data across endpoints, networks, and cloud

by Fortra · fortra.com · source ↗

Known CVEs (26)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-12164 ↗MEDIUM 4.42026

    Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while…

  • CVE-2026-12163 ↗MEDIUM 5.52026

    Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticat…

  • CVE-2026-9863 ↗HIGH 7.52026

    Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed cl…

  • CVE-2026-9862 ↗CRITICAL 9.82026

    Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to ca…

  • CVE-2026-1089 ↗MEDIUM 6.52026

    User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.

  • CVE-2026-0972 ↗MEDIUM 5.42026

    HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.

  • CVE-2026-0971 ↗MEDIUM 4.32026

    An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.

  • CVE-2025-1241 ↗MEDIUM 5.82026

    Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.

  • CVE-2025-14362 ↗HIGH 7.32026

    The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key…

  • CVE-2025-13532 ↗MEDIUM 6.22025

    Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.…

  • CVE-2025-8148 ↗MEDIUM 4.22025

    An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authenticatio…

  • CVE-2025-10035 ↗⚠ actively exploitedCRITICAL 10.02025

    A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, …

  • CVE-2025-8450 ↗HIGH 8.22025

    Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.

  • CVE-2025-3871 ↗MEDIUM 5.32025

    Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor a…

  • CVE-2025-5141 ↗MEDIUM 5.52025

    A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) a…

  • CVE-2024-11922 ↗MEDIUM 6.32025

    Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript…

  • CVE-2024-9945 ↗MEDIUM 5.32024

    An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.

  • CVE-2024-8264 ↗MEDIUM 5.52024

    Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.

  • CVE-2024-5276 ↗CRITICAL 9.82024

    A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion or modification of da…

  • CVE-2024-0259 ↗HIGH 7.32024

    Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is resta…

  • …and 6 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Data Loss Prevention products

see all →
  • Acronis DeviceLock DLP · Acronis International GmbH
  • Actifile Data Leakage Prevention · Actifile
  • Actifile Insider Threat Protection · Actifile
  • Agent Charley · Charlemagne Labs
  • AnySecura · AnySecura
  • Array Networks struXture™ InMotion · Array Networks
  • Atakama Browser Security - Data Leakage Control · Atakama
  • BatchPurifier · Digital Confidence