Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache commons Text Claris Claris filemaker Server |
|
| Vendors & Products |
Apache
Apache commons Text Claris Claris filemaker Server |
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published: 2025-12-16T18:07:37.371Z
Updated: 2025-12-17T04:56:10.082Z
Reserved: 2025-04-22T21:13:49.959Z
Link: CVE-2025-46295
Updated: 2025-12-16T19:32:59.531Z
Status : Received
Published: 2025-12-16T18:16:12.477
Modified: 2025-12-16T20:15:48.177
Link: CVE-2025-46295
No data.