CVE-2000-0385: Medium severity FileMaker Filemaker vulnerability
FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
FileMaker Pro 5 Web Companionfrom your environment.Uninstall or disable the FileMaker Pro 5 Web Companion component if it is not required.
- Configuration
Disable XML publishing in the Web Companion to prevent remote bypass of field-level database security.
FileMaker Pro 5 Web Companion XML publishing = disabled - Configuration
Disable the Web Companion's email capabilities to prevent remote bypass of field-level database security via email interfaces.
FileMaker Pro 5 Web Companion Email capabilities = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0385?
CVE-2000-0385 has been classified as a moderate severity vulnerability due to its ability to bypass security restrictions.
How do I fix CVE-2000-0385?
To fix CVE-2000-0385, update to the latest version of FileMaker Pro that addresses this vulnerability.
What software is affected by CVE-2000-0385?
CVE-2000-0385 affects FileMaker Pro version 5.0.
What type of attacks are possible with CVE-2000-0385?
CVE-2000-0385 allows remote attackers to bypass Field-Level database security restrictions.
Is there a workaround for CVE-2000-0385?
While there is no official workaround for CVE-2000-0385, restricting access to the Web Companion service may help mitigate the risk.