Support
File Security
New security updates
- Remotely exploitable vulnerability when using Web Publishing allows ability to view files on hosting system
- Upgrading to FileMaker 7: How to employ the new, advanced Security system
- FileMaker 7 Security
- Security considerations when sharing hosted databases
- Internet search engines and web publishing
- Considerations for sensitive information when importing XML data
- Correction to FileMaker Pro 6 "Web Security.PDF" regarding creating secure passwords
- FileMaker Pro 5.5 database files should be removed from the Web Companion web folder
Stay informed, be notified
The security of our customers' data is a top priority for FileMaker. Keep up with the latest security information concerning FileMaker products by subscribing to FileMaker Security News. Subscribe now .
Updated information about security considerations will also be published here as it becomes available. If you prefer not to subscribe to FileMaker Security News, please bookmark this page and visit often.
Security updates
| Overview | Created / revised |
|---|---|
|
Security article: Remotely exploitable vulnerability when using Web Publishing allows ability to view files on hosting system FileMaker Knowledge Base answer Problem summary: There is a remotely exploitable vulnerability for customers using web publishing that makes it possible for malicious users to view files on the hosting system. Who should read this article: Customers who are using the web publishing feature in FileMaker to share hosted FileMaker databases. Affected products:
Affected platforms:
Impact: This impacts any system that has employed FileMaker's web publishing and permits a malicious user to form a request that allows them to view other files on the hosting system. Update available: FileMaker Pro Web Companion 6.0v3 update addresses the above issue. Download update. |
Created: |
|
Security guide: Upgrading to FileMaker 7: How to employ the new, advanced Security system Who should read this guide: Customers who share hosted databases Affected products: FileMaker Pro 7, FileMaker Developer 7, FileMaker Server 7 ( scheduled to be available summer 2004) |
Created: |
|
White paper: FileMaker 7 Security Who should read this guide: Security experts, IT staff, and developers Affected products: FileMaker Pro 7, FileMaker Developer 7, FileMaker Server 7, and FileMaker Server 7 Advanced ( FileMaker Server 7 and FileMaker Server 7 Advanced are scheduled to be available summer 2004) Download the white paper (PDF) |
Created: |
|
Security article: Security considerations when sharing hosted databases FileMaker Knowledge Base Answer Problem summary: FileMaker hosts will send database passwords in an obscured format to FileMaker Pro clients during password verification. The client software performs the validation that a user-entered password is valid before allowing access to the database. This could create an opportunity for an attacker to obtain and use passwords. Who should read this article: Customers who are sharing hosted FileMaker databases. Affected products: FileMaker Pro 6.0 or earlier, FileMaker Pro 6.0 Unlimited or earlier FileMaker Server 5.5 or earlier |
Created: |
|
Security article: Internet search engines and web publishing FileMaker Knowledge Base Answer Problem summary: You may have read about Internet search engines' ability to identify computers publishing a FileMaker database over the web. This is not unique to FileMaker, and should not concern FileMaker customers if appropriate security guidelines are correctly followed. |
Created: |
|
Security article: Considerations for sensitive information when importing XML data FileMaker Knowledge Base Answer Problem summary:
Who should read this article: FileMaker Pro users
importing XML data or developing solutions to import XML
data. Affected products: FileMaker Pro 6 and FileMaker Pro 6
Unlimited (6.0v1, 6.0v2, 6.0v3) Update available:
|
Created: |
|
Security article: Correction to FileMaker Pro 6 "Web Security.PDF" regarding creating secure passwords FileMaker Knowledge Base Answer Problem summary: This document, which replaces previous versions of the "Web Publishing Security Guidelines," includes updates in Chapter 2 concerning tips for creating secure passwords. When FileMaker Pro databases are used individually, shared on a peer-to-peer basis, or shared using FileMaker Server, FileMaker Pro security consists of passwords and access privileges. Passwords protect access to your databases, and the access privileges associated with those passwords determine your guests' ability to create, edit, delete, or export records, design layouts, and so forth. This is a security model that is both simple and powerful. Who should read this article: Customers publishing databases to the Web with FileMaker. Affected products: FileMaker Pro 6 and FileMaker Pro 6 Unlimited. Update available: Download the corrected FileMaker Pro 6 document "WebSecurity.PDF" from the FileMaker website. A separate TechInfo article containing only the new password information which has been added to "Web Publishing Security Guidelines" is also available. Read " Tips for Creating Secure Passwords." |
Created: |
|
Security article: FileMaker Pro 5.5 database files should be removed from the Web Companion web folder FileMaker Knowledge Base Answer Problem summary: FileMaker Pro database files stored in the "web" folder (or subfolders) can be downloaded by end user browsers using HTTP requests, regardless of the settings in the Remote Administration options of the Web Companion Configuration, including "Requires password". Who should read this article: Customers publishing databases to the web with Web Companion in the FileMaker Pro 5.5 and FileMaker Pro 5.5 Unlimited products. Affected products: Web Companion 5.5 v2 and v3, with FileMaker Pro 5.5 or FileMaker Pro 5.5 Unlimited. Does not affect the Web Companion in FileMaker Pro 5.0, 4.1 or 4.0. Update available: FileMaker Pro Web Companion 5.5 v4 update addresses the issue. All supported language versions are now available. Download update. |
Created: Revised: |
Web Publishing Security Guidelines for FileMaker Pro 6 and FileMaker Pro 6 Unlimited
The security of our customers’ data is a top priority for FileMaker. To help you make your databases more secure, we have updated security guidelines for publishing FileMaker databases on the web.
It is very important to follow these web publishing guidelines, and other best practices for Internet security, to avoid inappropriately exposing data.
If you are publishing, or planning to publish, FileMaker databases on the web, be sure to review and implement the guidelines described in "Web Publishing Security Guidelines for FileMaker Pro 6 and FileMaker Pro 6 Unlimited" (please also read the related FAQ document). This document is the most current version of the "Web Security" PDF file for both FileMaker Pro 6 and FileMaker Pro 6 Unlimited. These web publishing security guidelines also provide information of interest to all users of FileMaker Pro, FileMaker Pro Unlimited and FileMaker Developer (6, 5.5 or earlier) who are publishing databases to the web.
For the protection of our customers, FileMaker does not disclose, discuss or confirm security issues until a full investigation has occurred and any necessary work arounds, patches or releases are available. FileMaker usually distributes information about security issues in its products through this site and the FileMaker Security News mailing list.