CVE-2022-38342
13.09.2022, 20:15
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data exfiltration or Server-Side Request Forgery (SSRF) attacks.Enginsight
Vendor | Product | Version |
---|---|---|
safe | fme_server | 𝑥 < 2021.2.6.0 |
safe | fme_server | 2022.0.0.0 ≤ 𝑥 < 2022.0.0.2 |
𝑥
= Vulnerable software versions
References