• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Zero-Day Vulnerability in Fortra’s GoAnywhere MFT Being Actively Exploited

    February 15, 2023 Alex Woodie

    A critical security vulnerability in Fortra’s (formerly HelpSystems) managed file transfer (MFT) solution, GoAnywhere MFT, is being actively exploited to steal data from companies and possibly even to spread ransomware according to published reports. Fortra told customers to consider every managed credential in their GoAnywhere environment to be compromised, shut down cloud instances of the service, and issued an emergency patch for the zero-day security vulnerability.

    Security reporter Brian Krebs was the first to share news of the vulnerability, which is described as remote code injection flaw that requires administrative console access for successful exploitation. In a February 2 post on Mastodon, Krebs shared the full text of the February 1 security advisory issued by Fortra, which is not available to the public.

    “A Zero-Day Remote Code Injection exploit was identified in GoAnywhere MFT,” Fortra said in its advisory. “The attack vector of this exploit requires access to the administrative console of the application, which in most cases is accessible only from within a private company network, through VPN, or by allow-listed IP addresses (when running in cloud environments, such as Azure or AWS).

    “If the administrative console is exposed to the public internet, it is highly recommended partnering with our customer support team to put in place appropriate access controls to limit trusted sources,” Fortra continues in its advisory. “The Web Client interface, which is normally accessible from the public internet, is not susceptible to this exploit, only the administrative interface.”

    NIST published a CVE entry on the vulnerability on February 6. CVE-2023-0669 details “a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.” On February 7, Fortra released a patch for the vulnerability with version 7.1.2 of GoAnywhere MFT, according to Rapid7, the Boston-based cybersecurity company listed as the source of the information in the CVE.

    “The Fortra advisory Krebs quoted advises GoAnywhere MFT customers to review all administrative users and monitor for unrecognized usernames, especially those created by system,” Rapid7 states in its February 3 blog post. “The logical deduction is that Fortra is likely seeing follow-on attacker behavior that includes the creation of new administrative or other users to take over or maintain persistence on vulnerable target systems.”

    The “attacker value” and the “exploitability” of the flaw is considered to be “very high,” Rapid7 noted in its February 6 technical analysis, which cited a security researcher from the Krebs post who found more than 1,000 GoAnywhere customers had exposed administrative ports to the public.

    The risk doesn’t appear to be theoretical, as a ransomware group has already claimed to have exploited more than 130 organizations using the vulnerability, according to a February 10 blog post on BleepingComputer. Sergiu Gatlan, a BleepingComputer reporter, says the Clop ransomware gang has taken credit for the hack.

    “Clop reached out to BleepingComputer and told us that they had allegedly stolen the data over the course of 10 days after breaching servers vulnerable to exploits targeting this bug,” Gatlan wrote. “They also claimed that they could move laterally through their victims’ networks and deploy ransomware payloads to encrypt their systems but decided against it and only stole the documents stored on the compromised GoAnywhere MFT servers.”

    GoAnywhere MFT was acquired by Fortra back in 2016, when the Eden Prairie, Minnesota, company still went by the name HelpSystems. The Java-based product, which was originally developed by Linoma Software, enables uses to securely exchange files via various protocols, including FTP, FTPS, SFTP, HTTP, HTTPS, SMTP, POP3. The software runs natively on IBM i, Windows, Linux, and other operating systems.

    Linoma is one of dozens of security-focused tool and services vendors acquired by Fortra over the years. In November 2022, HelpSystems decided to change its name to Fortra, which the company said better reflected its focus on security.

    A Fortra spokesperson responded to IT Jungle’s questions with the following statement:

    “On January 30, 2023, we were made aware of suspicious activity within certain instances of our GoAnywhere MFTaaS solution. We immediately took multiple steps to address this, including implementing a temporary outage of this service to prevent any further unauthorized activity, notifying all customers who may have been impacted, and sharing mitigation guidance, which includes instructions to our on-prem customers about applying our recently developed patch.

    “Additionally, we coordinated with CISA to add information about this vulnerability to their CVE catalog to broaden the reach of information about this issue.  We are taking this very seriously and continue to help our customers implement mitigation steps to address this issue.”

    Editor’s note: This story was updated on February 15 with a comment from Fortra.

    RELATED STORIES

    Security Still Top Concern, IBM i Marketplace Study Says

    How HelpSystems Became Fortra

    HelpSystems Fills Encryption Gap With Linoma Buy

    Share this:

    • Share on Reddit (Opens in new window) Reddit
    • Share on Facebook (Opens in new window) Facebook
    • Share on LinkedIn (Opens in new window) LinkedIn
    • Share on X (Opens in new window) X
    • Email a link to a friend (Opens in new window) Email

    Tags: Tags: Fortra, FTP, FTPS, GoAnywhere MFT, HelpSystems, HTTP, HTTPS, IBM i, Java, Linoma Software, POP3, SFTP, SMTP

    Sponsored by
    JAMS Software

    One Scheduler. IBM i, Windows, Linux, and More.

    IBM i teams trust JAMS to schedule and orchestrate jobs across every platform in their environment. Centralized visibility, cross-platform dependency management, and alerts that reach the right person before the business feels it.

    Fewer than 5% of IBM i shops run IBM i only. The rest are managing cross-platform dependencies — often without a clear picture of how they connect. JAMS draws that map, enforces those dependencies automatically, and gives your team a single place to monitor, manage, and recover when something goes wrong.

    If you are running hundreds of CL scripts and custom RPG processes, bring them as-is. JAMS runs them exactly as they do today — except now they are visible, monitored, and part of an orchestrated workflow instead of scattered across folders only one person knows about.

    No consumption-based pricing. No surprise bills when your workload spikes. You pay based on how many machines JAMS talks to — that’s it.

    Learn More → https://jamsscheduler.com/lp/ibm-i

    Share this:

    • Share on Reddit (Opens in new window) Reddit
    • Share on Facebook (Opens in new window) Facebook
    • Share on LinkedIn (Opens in new window) LinkedIn
    • Share on X (Opens in new window) X
    • Email a link to a friend (Opens in new window) Email

    Getting Ready for IBM i Cloud Migrations IBM’s Power Systems Battle Plan To Take On 2023

    Leave a ReplyCancel reply

TFH Volume: 33 Issue: 10

This Issue Sponsored By

  • Maxava
  • New Generation Software
  • ARCAD Software
  • Computer Keyes
  • Raz-Lee Security

Table of Contents

  • IBM’s Power Systems Battle Plan To Take On 2023
  • Zero-Day Vulnerability in Fortra’s GoAnywhere MFT Being Actively Exploited
  • Getting Ready for IBM i Cloud Migrations
  • Four Hundred Monitor, February 15
  • IBM i Debugger Comes to VS Code

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Inside The Encryption Key Management Changes In IBM i 7.6
  • FalconStor Moved To The Blue Lagoon, And Is Poised For Growth Because Of It
  • Guru: Claude’s SQL Tip
  • Astera Makes Extracting Legacy Report Data an AI Specialty
  • IBM i PTF Guide, Volume 28, Number 27
  • Welcoming The New IBM i Chief Architect And Other New Top Brass
  • A Deep Dive Into That Power S1112 Entry Power11 Server
  • Guru: Beyond Three-Part Naming – Running SQL Across Remote IBM i Systems
  • How IBM Bolstered IBM i Resilience In The Summer Tech Refreshes
  • IBM i PTF Guide, Volume 28, Number 26

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle