An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs. This vulnerability has been fully addressed in FileMaker Server 22.0.4.
References
| Link | Resource |
|---|---|
| https://support.claris.com/s/answerview?anum=000049056&language=en_US | Vendor Advisory |
Configurations
History
23 Dec 2025, 14:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:* | |
| First Time |
Claris
Claris filemaker Server |
|
| References | () https://support.claris.com/s/answerview?anum=000049056&language=en_US - Vendor Advisory |
16 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-285 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
16 Dec 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-16 18:16
Updated : 2025-12-23 14:45
NVD link : CVE-2025-46296
Mitre link : CVE-2025-46296
CVE.ORG link : CVE-2025-46296
JSON object : View
Products Affected
claris
- filemaker_server
CWE
CWE-285
Improper Authorization
