PT-2022-24380 · Safe · Fme Server

Published

2022-09-13

·

Updated

2022-10-27

·

CVE-2022-38342

CVSS v3.1

8.5

High

VectorAC:L/AV:N/A:N/C:H/I:L/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Safe Software FME Server versions prior to v2022.0.1.1
Description The issue allows authenticated attackers to perform data exfiltration or Server-Side Request Forgery (SSRF) attacks due to a XML External Entity (XXE) vulnerability.
Recommendations For versions prior to v2022.0.1.1, update to a version above v2022.0.1.1 to resolve the issue.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-38342

Affected Products

Fme Server