CVE-2025-46295: Code Injection
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46295?
CVE-2025-46295 is classified as a high severity vulnerability due to its potential to allow attackers to execute commands or access external resources.
How do I fix CVE-2025-46295?
To mitigate CVE-2025-46295, upgrade to Apache Commons Text version 1.10.0 or later.
What are the affected versions in CVE-2025-46295?
CVE-2025-46295 affects Apache Commons Text versions prior to 1.10.0 and FileMaker Server up to version 22.0.4.
Is CVE-2025-46295 exploitable remotely?
Yes, CVE-2025-46295 can be exploited remotely if untrusted input is passed to the text-substitution API.
What are the risks of CVE-2025-46295?
The risks of CVE-2025-46295 include unauthorized command execution and unauthorized access to external resources.