CVE-2014-8347
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
11/02/2020
Last modified:
17/06/2026
Description
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:claris:filemaker_pro:13.03:*:*:*:*:*:*:* | ||
| cpe:2.3:a:claris:filemaker_pro_advanced:12.0.4.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/128853/Filemaker-Login-Bypass-Privilege-Escalation.html
- http://www.exploit-db.com/exploits/35077
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97780
- https://lists.openwall.net/bugtraq/2014/10/27/4
- https://www.securityfocus.com/archive/1/533814
- http://packetstormsecurity.com/files/128853/Filemaker-Login-Bypass-Privilege-Escalation.html
- http://www.exploit-db.com/exploits/35077
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97780
- https://lists.openwall.net/bugtraq/2014/10/27/4
- https://www.securityfocus.com/archive/1/533814



