Skip to main content

Hi,

 

We are deploying FME Desktop 2022.2 in our server (it’s a virtual machine).  The security team had done a security scan and expected us to upgrade the FlexNet Publisher to version 11.19.6.0 or later. However, the FlexNet installer downloaded from this link (https://fme.safe.com/downloads/) is Build 11.19.2. And it looks like bonding with FME Desktop so that we cannot upgrade FlexNet Publisher individually. 


How can I upgrade the version of FlexNet to version 11.19.6.0 or later? Thanks in advance.

 

Best Regards,

Qubbie

Hi @qubbiewu 

Is this related to CVE-2024-2658? 

CVE-2024-2658 is very specific to FlexNet Publisher's lmadmin license management utility, which we don't ship with our installer. Instead, we ship the lighter-weight lmgrd management utility. 

So the Safe Software FlexNet Publisher install isn't affected by the CVE. 
But, out of an abundance of caution, we do have an internal service ticket cinternal: DEVOPS-5071] filed to upgrade our FlexNet Publisher version to 11.19.6.

 

Crystal 


Dear Crystal,

 

Yes, it’s related to CVE-2024-2658. 

Noted and thank you for your reply. 

 

Regards,

Qubbie


No problem @qubbiewu 

I will send an update once we have upgraded to 11.19.6. 

 

Crystal


Reply