Fme Server
Vendor:
First CVE: Dec 23, 2018 · Active for 7 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fme Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2018
7 years ago
Most Recent CVE
Jun 23, 2023
1,127 days ago
CVE Severity & Scoring
Fme Server8 CVEs
50%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low5 (62.5%)
High1 (12.5%)
None2 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20402HIGH Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account. The passwords to the three accounts are the | Dec 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2022-38340HIGH Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload. | Sep 20, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-38341HIGH Safe Software FME Server v2021.2.5 and below does not employ server-side validation. | Sep 19, 2022 | 7.1 | 24 | NO | NO |
CVE-2023-35801HIGH A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting | Jun 23, 2023 | 8.1 | 23 | NO | NO |
CVE-2022-38339MEDIUM Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a | Sep 19, 2022 | 6.1 | 23 | NO | NO |
CVE-2020-22789MEDIUM Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login p | Apr 28, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-22790MEDIUM Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of t | Apr 28, 2021 | 5.4 | 19 | NO | NO |
CVE-2022-38342MEDIUM Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data e | Sep 13, 2022 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Fme Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2020.0 | 2 | 5.8 | 1.3% | 0 | 0 |
| 2019.2 | 2 | 5.8 | 1.3% | 0 | 0 |
| 2019.1 | 2 | 5.8 | 1.3% | 0 | 0 |
| 2019.0 | 2 | 5.8 | 1.3% | 0 | 0 |