CVE-2014-5321
FileMaker Pro before 13 and Pro Advanced before 13 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2319.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5321?
CVE-2014-5321 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-5321?
To fix CVE-2014-5321, upgrade to FileMaker Pro 13 or later versions that properly verify X.509 certificates.
What systems are affected by CVE-2014-5321?
CVE-2014-5321 affects FileMaker Pro and FileMaker Pro Advanced versions prior to 13.
What is the impact of CVE-2014-5321?
The impact of CVE-2014-5321 allows attackers to spoof servers and potentially gain access to sensitive information.
Is there a public exploit for CVE-2014-5321?
As of now, there are no public exploits specifically known for CVE-2014-5321 reported.