Skip to main content
Solved

Is FME Server / Flow vulnerable for Apache ActiveMQ CVE-2023-46604 https://www.cve.org/CVERecord?id=CVE-2023-46604

  • October 30, 2023
  • 2 replies
  • 90 views

gtiemens
Is FME Server / Flow vulnerable for Apache ActiveMQ CVE-2023-46604 https://www.cve.org/CVERecord?id=CVE-2023-46604

Best answer by keziaatsafe

According to our assessment, we believe that the only component in FME Form and FME Flow possibly affected by this vulnerability is the JMSSender/Receiver (Form) & JMS Subscriber/Publisher (Flow). We do not expect your workspaces or automation workflows to be affected if you’re not using either of these transformers.

That being said, Apache ActiveMQ will be upgraded to a non-vulnerable version for the 2023.2 and 2024.0+ releases. We will also backport the fix to a 2023.1.2 release.

 

This post is closed to further activity.
It may be an old question, an answered question, an implemented idea, or a notification-only post.
Please check post dates before relying on any information in a question or answer.
For follow-up or related questions, please post a new question or idea.
If there is a genuine update to be made, please contact us and request that the post is reopened.

2 replies

keziaatsafe
Safer
Forum|alt.badge.img+8
  • Safer
  • 153 replies
  • November 7, 2023

Hi @gtiemens​ ,

Thank you for contacting Safe Software and for reporting this vulnerability.  

Our team is currently investigating the vulnerability CVE-2023-46604 to determine if FME Form and Flow are affected.

I will update this thread as soon as I have further information. 

Thank you for your patience.

Kezia


keziaatsafe
Safer
Forum|alt.badge.img+8
  • Safer
  • 153 replies
  • Best Answer
  • November 9, 2023

According to our assessment, we believe that the only component in FME Form and FME Flow possibly affected by this vulnerability is the JMSSender/Receiver (Form) & JMS Subscriber/Publisher (Flow). We do not expect your workspaces or automation workflows to be affected if you’re not using either of these transformers.

That being said, Apache ActiveMQ will be upgraded to a non-vulnerable version for the 2023.2 and 2024.0+ releases. We will also backport the fix to a 2023.1.2 release.