9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4.
AI Analysis
Remote code execution vulnerability in Apache Commons Text due to interpolation features
Basic Information
ID
CVE-2025-46295
Source
apple
Published
Dec 16, 2025 at 18:07
Modified
Dec 16, 2025 at 19:35
Affected Product
Vendor
Claris
Product
FileMaker Server
Version
unspecified
Affected Versions
Claris FileMaker Server unspecified
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Claris
Product
FileMaker Server
Version
unspecified