Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-35801

    A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting in the unauthorized reading and writing of arbitrary files. Successful exploitation requires an attacker to have access to a user account with write privileges. FME Flow 2023.0 is also a fixed version.

    Last Modified: Nov 29, 2024
    Published: Jun 23, 2023

    CVE-2022-38340

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.

    Last Modified: May 29, 2025
    Published: Sep 20, 2022

    CVE-2022-38339

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page.

    Last Modified: Nov 21, 2024
    Published: Sep 19, 2022

    CVE-2022-38341

    Safe Software FME Server v2021.2.5 and below does not employ server-side validation.

    Last Modified: Nov 21, 2024
    Published: Sep 19, 2022

    CVE-2022-38342

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data exfiltration or Server-Side Request Forgery (SSRF) attacks.

    Last Modified: Nov 21, 2024
    Published: Sep 13, 2022
    Items Per Page