A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting in the unauthorized reading and writing of arbitrary files. Successful exploitation requires an attacker to have access to a user account with write privileges. FME Flow 2023.0 is also a fixed version.
References
Link | Resource |
---|---|
https://community.safe.com/s/ | Product |
https://community.safe.com/s/article/Known-Issue-FME-Flow-Directory-Traversal-Vulnerability | Mitigation Vendor Advisory |
https://downloads.safe.com/fme/2023/whatsnew_server_2023_0_0_3.txt | Release Notes |
https://community.safe.com/s/ | Product |
https://community.safe.com/s/article/Known-Issue-FME-Flow-Directory-Traversal-Vulnerability | Mitigation Vendor Advisory |
https://downloads.safe.com/fme/2023/whatsnew_server_2023_0_0_3.txt | Release Notes |
Configurations
History
21 Nov 2024, 08:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://community.safe.com/s/ - Product | |
References | () https://community.safe.com/s/article/Known-Issue-FME-Flow-Directory-Traversal-Vulnerability - Mitigation, Vendor Advisory | |
References | () https://downloads.safe.com/fme/2023/whatsnew_server_2023_0_0_3.txt - Release Notes |
05 Jul 2023, 16:22
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-23 06:15
Updated : 2024-11-21 08:08
NVD link : CVE-2023-35801
Mitre link : CVE-2023-35801
CVE.ORG link : CVE-2023-35801
JSON object : View
Products Affected
safe
- fme_server
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')