CVE-2024-27790
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27790?
The severity of CVE-2024-27790 is classified as critical due to the potential for unauthorized access to sensitive database records.
How do I fix CVE-2024-27790?
To fix CVE-2024-27790, update FileMaker Server to version 20.3.2 or later.
What types of records are affected by CVE-2024-27790?
CVE-2024-27790 potentially allows unauthorized access to database records stored on FileMaker Server.
Is CVE-2024-27790 a remote attack vector?
Yes, CVE-2024-27790 can be exploited remotely through client requests to the FileMaker Server.
When was CVE-2024-27790 disclosed?
CVE-2024-27790 was disclosed when Claris International released version 20.3.2 to address the vulnerability.