---
cve: "CVE-2024-27790"
severity: "HIGH"
cvss: 7.5
epss: "46%"
vendor: "Claris"
kev: false
exploited: false
published: "2024-05-14 15:13:01"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T19:30:32+02:00"
---

# CVE-2024-27790

> 7.5 HIGH

## Beschreibung

Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://support.claris.com/s/answerview?anum=000041674&language=en_US>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-27790) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
