threat
engine
.sh
Back
·
··:··
Home
/
Product
/
safe fme server
Product
safe fme server
8 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-35801
< 2022.2.5
A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editi
8.1
HIGH
CVE-2022-38340
< 2021.2.6
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the compone
9.1
CRITICAL
CVE-2022-38339
< 2021.2.6
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attacke
9.6
CRITICAL
CVE-2022-38341
>= 2021.2.3 and < 2021.2.6
Safe Software FME Server v2021.2.5 and below does not employ server-side validation.
7.1
HIGH
CVE-2022-38342
< 2021.2.6.0
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability whic
8.5
HIGH
CVE-2020-22790
all versions
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitr
5.4
MEDIUM
CVE-2020-22789
all versions
Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by inje
6.1
MEDIUM
CVE-2018-20402
<= 2018.1
Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator acc
8.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin