FME and CVE-2021-44228

By Published On: December 14, 2021

On the 10th of December, details regarding a new security […]

On the 10th of December, details regarding a new security vulnerability identified as CVE-2021-44228 (aka Log4Shell aka LogJam) were released.  This issue is generating considerable media attention and further information can be found here.

Seamless are in close contact with Safe Software who have reviewed the issue and checked for vulnerabilities. Safe are confident that their implementation in FME Server is not susceptible to this vulnerability.  However, out of an abundance of caution, they are upgrading the component for FME Server 2022 and 2021.2.x.  They do not have any concerns for FME Server 2020 (and older) and will not be issuing patches for those versions at this time.  You can read Safe Softwares article here.

This means at this stage, you do not need to take any actions on your FME Server of FME Cloud instances.

In regards, to all of FME Server’s powerful logging capabilities – these use a proprietary solution built by Safe Software, so please be assured that this is not affected by this issue.

If the situation evolves and we received further updates, or should there be a change that directly impacts your FME server, we will update this post.

If you have any questions or concerns do not hesitate to reach out to us.

Want to be notified about what we’ve been up to?

    Sign up for our newsletter