Skip to main content
Solved

FME Server and Spring4Shell vulnerability


kjetilpettersso
Contributor
Forum|alt.badge.img+1

Is FME Server affected by the recent vulnerability discovered in Spring Core?

 

https://www.contrastsecurity.com/security-influencers/new-spring4shell-vulnerability-confirmed-what-it-is-and-how-to-be-prepared

Best answer by keziaatsafe

Hi @kjetilpettersso​ ,

 

We will continue to investigate and will update our guidance as new information becomes available. Please see this article, Spring4Shell Vulnerability: Is FME Impacted?.

 

In our initial review, the vulnerability requires Java 9 +. FME Server is running with Java 8 and therefore does not meet the requirements to be affected by this vulnerability.

 

Our team has reviewed the "Spring4Shell" vulnerability and other vulnerabilities recently discovered in the Spring Framework. We are confident that our implementation is not susceptible to the vulnerabilities described as CVE-2022-22965, CVE-2022-22963, and CVE-2022-22950.

 

 

Thank you.

View original
Did this help you find an answer to your question?

2 replies

keziaatsafe
Safer
Forum|alt.badge.img+7
  • Safer
  • Best Answer
  • March 31, 2022

Hi @kjetilpettersso​ ,

 

We will continue to investigate and will update our guidance as new information becomes available. Please see this article, Spring4Shell Vulnerability: Is FME Impacted?.

 

In our initial review, the vulnerability requires Java 9 +. FME Server is running with Java 8 and therefore does not meet the requirements to be affected by this vulnerability.

 

Our team has reviewed the "Spring4Shell" vulnerability and other vulnerabilities recently discovered in the Spring Framework. We are confident that our implementation is not susceptible to the vulnerabilities described as CVE-2022-22965, CVE-2022-22963, and CVE-2022-22950.

 

 

Thank you.


kjetilpettersso
Contributor
Forum|alt.badge.img+1

@keziaatsafe​  Thank you!


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings