CVE-2020-22790
Safe Software FME Flow vulnerability analysis and mitigation

Overview

CVE-2020-22790 is an Authenticated Stored Cross-Site Scripting (XSS) vulnerability affecting FME Server versions 2019.2 and 2020.0 Beta. The vulnerability allows a remote attacker to execute code by injecting arbitrary web script or HTML via modifying the name of users. The vulnerability is triggered when an administrator accesses the logs (NVD, Mexican Pentester).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). It has a CVSS v3.1 Base Score of 5.4 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The CVSS v2.0 Base Score is 3.5 (Low) with vector (AV:N/AC:M/Au:S/C:N/I:P/A:N). The vulnerability exists because the application fails to properly sanitize user input in the name fields when creating, deleting, or modifying users, which is then displayed in the logs without proper output encoding (NVD).

Impact

When exploited, this vulnerability allows an authenticated attacker to inject malicious web scripts or HTML that gets executed when an administrator views the logs. This could potentially lead to the compromise of administrator sessions and access to sensitive information (NVD).

Mitigation and workarounds

The vulnerability has been addressed in subsequent versions of FME Server. Users are advised to upgrade to a patched version of the software. The vendor has acknowledged the vulnerability and provided security updates (Safe Community).

Additional resources


SourceThis report was generated using AI

Related Safe Software FME Flow vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-35801HIGH8.1
  • Safe Software FME FlowSafe Software FME Flow
  • cpe:2.3:a:safe:fme_server
NoYesJun 23, 2023
CVE-2022-38340HIGH7.2
  • Safe Software FME FlowSafe Software FME Flow
  • cpe:2.3:a:safe:fme_server
NoYesSep 20, 2022
CVE-2022-38341HIGH7.1
  • Safe Software FME FlowSafe Software FME Flow
  • cpe:2.3:a:safe:fme_server
NoYesSep 19, 2022
CVE-2022-38342MEDIUM6.5
  • Safe Software FME FlowSafe Software FME Flow
  • cpe:2.3:a:safe:fme_server
NoYesSep 13, 2022
CVE-2022-38339MEDIUM6.1
  • Safe Software FME FlowSafe Software FME Flow
  • cpe:2.3:a:safe:fme_server
NoYesSep 19, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management