PT-2024-22034 · Clarisa · Filemaker Server

Published

2024-04-26

·

Updated

2024-12-09

·

CVE-2024-27790

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FileMaker Server versions prior to 20.3.2
Description The issue potentially allowed unauthorized access to records stored in databases hosted on FileMaker Server. This was resolved by validating transactions before replying to client requests.
Recommendations For versions prior to 20.3.2, update to FileMaker Server 20.3.2 to fix the issue by validating transactions before replying to client requests.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-27790

Affected Products

Filemaker Server