PT-2024-13068 · Clarisa · Filemaker Server

Published

2024-04-26

·

Updated

2024-12-10

·

CVE-2023-42955

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions FileMaker Server versions prior to 20.3.1
Description The issue potentially exposed password information to front-end websites when signed in to the Admin Console with an administrator role. This was resolved by eliminating the send of Admin Role passwords in the Node.js socket.
Recommendations For versions prior to 20.3.1, update to FileMaker Server 20.3.1 to resolve the issue. As a temporary workaround, consider restricting access to the Admin Console to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-42955

Affected Products

Filemaker Server