PT-2024-13068 · Clarisa · Filemaker Server

CVE-2023-42955

·

Published

2024-04-26

·

Updated

2024-12-10

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions FileMaker Server versions prior to 20.3.1
Description The issue potentially exposed password information to front-end websites when signed in to the Admin Console with an administrator role. This was resolved by eliminating the send of Admin Role passwords in the Node.js socket.
Recommendations For versions prior to 20.3.1, update to FileMaker Server 20.3.1 to resolve the issue. As a temporary workaround, consider restricting access to the Admin Console to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-42955

Affected Products

Filemaker Server