PT-2022-24380 · Safe · Fme Server
Published
2022-09-13
·
Updated
2022-10-27
·
CVE-2022-38342
CVSS v3.1
8.5
High
| Vector | AC:L/AV:N/A:N/C:H/I:L/PR:L/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
Safe Software FME Server versions prior to v2022.0.1.1
Description
The issue allows authenticated attackers to perform data exfiltration or Server-Side Request Forgery (SSRF) attacks due to a XML External Entity (XXE) vulnerability.
Recommendations
For versions prior to v2022.0.1.1, update to a version above v2022.0.1.1 to resolve the issue.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fme Server