Solved

Is FME Server / Flow vulnerable for Apache ActiveMQ CVE-2023-46604 https://www.cve.org/CVERecord?id=CVE-2023-46604

  • 30 October 2023
  • 2 replies
  • 18 views

Is FME Server / Flow vulnerable for Apache ActiveMQ CVE-2023-46604 https://www.cve.org/CVERecord?id=CVE-2023-46604
icon

Best answer by keziaatsafe 9 November 2023, 18:23

View original

2 replies

Userlevel 1
Badge +6

Hi @gtiemens​ ,

Thank you for contacting Safe Software and for reporting this vulnerability.  

Our team is currently investigating the vulnerability CVE-2023-46604 to determine if FME Form and Flow are affected.

I will update this thread as soon as I have further information. 

Thank you for your patience.

Kezia

Userlevel 1
Badge +6

According to our assessment, we believe that the only component in FME Form and FME Flow possibly affected by this vulnerability is the JMSSender/Receiver (Form) & JMS Subscriber/Publisher (Flow). We do not expect your workspaces or automation workflows to be affected if you’re not using either of these transformers.

That being said, Apache ActiveMQ will be upgraded to a non-vulnerable version for the 2023.2 and 2024.0+ releases. We will also backport the fix to a 2023.1.2 release.

 

Reply