Skip to main content
Question

Manual patch for security vulnerability - how to replace files ensuring permissions

  • September 10, 2026
  • 3 replies
  • 53 views

catherinep
Participant
Forum|alt.badge.img+1

Hello

We have FME Server v2022.2.2 installed on Windows 2022 server and need to apply manual patch for security vulnerability, as per FME alert / article

https://support.safe.com/hc/en-us/articles/31265482270349-Security-Update-FME-Flow-Privilege-Escalation-Vulnerability#h_01JB2AENHZEBG9VCCFBJFTWX1R

The instructions include a note:

*When moving/overwriting files, please ensure that the original permissions of the file being overwritten are preserved, this is ./opt/fmeflow.

How best to do this?  We were planning on a simple copy and paste of the files themselves to the various directories, however this may overwrite existing permissions.  

What method of copy & replace files is recommended, it would be helpful if the windows command or powershell script could be provided to assist 

Please advise

Thanks 

3 replies

zoe.forbes
Safer
Forum|alt.badge.img+10
  • Safer
  • September 11, 2026

Hi ​@catherinep,

All files within the install directory <FMEFlowDir> should have the same permissions. Since it sounds like you’re on Windows, this is located at C:\Program Files\FMEFlow\ by default. 

From our Permissions docs page, Read/Write permissions on <FMEFlowDir> are required for the account which runs the Core, Engines and Web App Server. You can check which account is running these in Services:

To ensure permissions are correct, you have two options:

  1. Paste in the patch files, and check each file’s permissions individually.
  2. Paste in all of the patch files, and set permissions (with inheritance) at the directory level.

We generally recommend restarting Flow after making permission changes. 

Please let me know if you have any more questions about this! I’m happy to go into more detail if anything’s unclear. 


catherinep
Participant
Forum|alt.badge.img+1
  • Author
  • Participant
  • September 16, 2026

Thanks for the reply.  

To update this request: we successfully applied the manual patch to our instance of FME Server v2022.2.  We simply used copy and paste to update the individual files with the Program Files directory in the relevant directories - C:\Program Files\FMEServer\Utilities\tomcat\webapps\fmeapiv4\WEB-INF

The destination directory permissions remained unchanged, and the newer versions of the files maintained the same file permission.  

FME Server restarted and working as normal post the manual patching.  

 


zoe.forbes
Safer
Forum|alt.badge.img+10
  • Safer
  • September 16, 2026

Glad to hear everything’s working @catherinep! Just realised I forgot to mention in my last message that 2022 is outside of our three-year support scope so we highly recommend upgrading. There’s a great deal of new features, bug fixes, and important security updates in newer versions.

You’re more than welcome to continue asking questions here on the Community regardless of version, but we’ll be very limited in the help we can provide over Customer Support.