PT-2020-7751 · Clarisa · Filemaker Pro+1
Published
2020-02-11
·
Updated
2020-02-13
·
CVE-2014-8347
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Filemaker Pro version 13.03
Filemaker Pro Advanced version 12.04
Description
An issue exists in the
MatchPasswordData function within DBEngine.dll, potentially allowing a malicious user to bypass authentication and obtain elevated privileges.Recommendations
For Filemaker Pro version 13.03, update to a version that fixes the issue in the
MatchPasswordData function.
For Filemaker Pro Advanced version 12.04, update to a version that fixes the issue in the MatchPasswordData function.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filemaker Pro
Filemaker Pro Advanced