Skip to main content
Solved

Is FME Server affected by CVE-2022-42889 (Apache Commons Text versions 1.5 through 1.9)

  • October 21, 2022
  • 1 reply
  • 31 views

Hello,

Is there any info if FME server is affected by new vulnerability CVE-2022-42889 (Apache Commons Text versions 1.5 through 1.9)?

Best answer by keziaatsafe

Hi @dominikw​ ,

Our team has reviewed CVE-2022-42889 and can confirm that FME is not affected by this vulnerability.

FME Desktop and Engine do not use Apache Commons Text and FME Server is not shipped with Apache Commons Text.

 

Thanks,

Kezia

This post is closed to further activity.
It may be an old question, an answered question, an implemented idea, or a notification-only post.
Please check post dates before relying on any information in a question or answer.
For follow-up or related questions, please post a new question or idea.
If there is a genuine update to be made, please contact us and request that the post is reopened.

1 reply

keziaatsafe
Safer
Forum|alt.badge.img+8
  • Safer
  • Best Answer
  • October 21, 2022

Hi @dominikw​ ,

Our team has reviewed CVE-2022-42889 and can confirm that FME is not affected by this vulnerability.

FME Desktop and Engine do not use Apache Commons Text and FME Server is not shipped with Apache Commons Text.

 

Thanks,

Kezia