Overview
FileMaker may expose data inadvertently.
Description
FileMaker Web Companion prior to version 5.0v4 permits unauthorized access to data even if the database manager believes that data is protected by Field Level Security. |
Impact
Attackers can read information, including items such as passwords, stored in databases thought to be protected. |
Solution
Upgrade to 5.0v4 or later as described in http://www.filemaker.com/support/webcompanion_archive.html#may9. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Our thanks to Erik C. Thauvin, of Blue World Communications, Inc., who reported this problem to us.
This document was written by Shawn V Hernan.
Other Information
CVE IDs: | CVE-2000-0385 |
Severity Metric: | 12.00 |
Date Public: | 2000-05-01 |
Date First Published: | 2000-12-15 |
Date Last Updated: | 2001-01-17 05:16 UTC |
Document Revision: | 10 |