CVE-2021-44147: XEE
Published Nov 22, 2021
·Updated
An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.
Affected Software
2 affected components
Claris FileMaker Pro<19.4.1
Claris FileMaker Server<19.4.1
Event History
Nov 22, 2021
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-44147.
2
What is the affected software?
The affected software includes Claris FileMaker Pro and Server (including WebDirect) versions up to and exclusive of 19.4.1.
3
How does this vulnerability impact the system?
This vulnerability allows a remote attacker to disclose local files and perform server-side request forgery attacks.
4
What is the severity rating of CVE-2021-44147?
CVE-2021-44147 has a severity rating of 5.5 (medium).
5
How can I fix this vulnerability?
To fix this vulnerability, update Claris FileMaker Pro and Server to version 19.4.1 or later.