Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
CVE Vulnerabilities
CVE-2022-38341
Published:
Sep 19, 2022
| Modified:
Nov 07, 2023
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
Additional information
NVD
https://nvd.nist.gov/vuln/detail/CVE-2022-38341
CWE
https://cwe.mitre.org/data/definitions/NVD-Other.html
Safe Software FME Server v2021.2.5 and below does not employ server-side validation.
Affected Software
Name
Vendor
Start Version
End Version
Fme_server
Safe
2021.2.3 (including)
2021.2.6 (excluding)
References
https://community.safe.com/s/article/Known-Issue-Lack-of-server-side-validation-when-creating-a-new-user-in-FME-Server
https://www.cycura.com/blog/safe-software-inc-fme-server-vulnerability-disclosure/
Aqua Container Security