8.1
CVSSv3

CVE-2023-35801

Published: 23/06/2023 Updated: 05/07/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A directory traversal vulnerability in Safe Software FME Server prior to 2022.2.5 allows an malicious user to bypass validation when editing a network-based resource connection, resulting in the unauthorized reading and writing of arbitrary files. Successful exploitation requires an malicious user to have access to a user account with write privileges. FME Flow 2023.0 is also a fixed version.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

safe fme server