PT-2022-24376 · Safe · Fme Server

Published

2022-09-19

·

Updated

2022-11-03

·

CVE-2022-38339

CVSS v3.1

9.6

Critical

VectorAC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:R
Name of the Vulnerable Software and Affected Versions Safe Software FME Server versions prior to v2022.0.1.1
Description The issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page, specifically through a cross-site scripting (XSS) vulnerability. This enables attackers to potentially steal user sessions, deface websites, or redirect the user to malicious sites.
Recommendations For versions prior to v2022.0.1.1, as a temporary workaround, consider restricting access to the login page until a patch is available. Avoid using the login functionality with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-38339

Affected Products

Fme Server