SlideShare uma empresa Scribd logo
1 de 17
Baixar para ler offline
FileMaker Server 14.0.4
Security Updates
2015/12/20
Lightning Talk in FM-Tokyo
Atsushi Matsuo (Emic Corporation)
FileMaker Server 14.0.4
FileMaker Server 14.0.4
• Includes security updates
- from FileMaker Knowldge Base
FileMaker Server 14.0.4
1. Addressed an issue related to the
expiration of the default SSL certificate.
- from FileMaker Knowldge Base
FileMaker Server 14.0.4
2. Addressed an issue with the Technology
Tests page link that tests Custom Web
Publishing with PHP.
- from FileMaker Knowldge Base
FileMaker Server 14.0.4
• Fix XSS of the Technology Tests page that
tests Custom Web Publishing with PHP
• Affected: FileMaker Server 9, 10, 11, 12,
13, 14.0.1, 14.0.2, 14.0.3 (when enabling
Custom Web Publishing with PHP)
• Workaround: Remove "phptest.php" file
- from results of my investigation
FileMaker Server 14.0.4
3. For FileMaker WebDirect and Custom Web
Publishing content to display in <iframe>
tags of separate webpages, those webpages
must also be hosted by the FileMaker
Server web server.Webpages hosted by
other web servers cannot use the <iframe>
tag to embed FileMaker WebDirect and
Custom Web Publishing content.
- from FileMaker Knowldge Base
FileMaker Server 14.0.4
• The web server of FileMaker Server 14.0.4
outputs "X-Frame-Options: SAMEORIGIN"
HTTP header in order to prevente
clickjacking
- from results of my investigation
FileMaker Server 14.0.4a
FileMaker Server 14.0.4a
Software Patch
• This software provides security fixes for
FileMaker Server 14.0.4
- from FileMaker Knowldge Base
FileMaker Server 14.0.4a
Software Patch
1. Updates the third-party component
OpenSSL.
- from FileMaker Knowldge Base
FileMaker Server 14.0.4a
Software Patch
2. Updates the third-party component Java to
Java 8 Update 66, including a critical patch
update.
- from FileMaker Knowldge Base
FileMaker Server 14.0.4a
Software Patch
3. OS X El Capitan version 10.11:Addressed
an issue where scripts using the Insert
From URL script step returned an SSL
certificate error.
- from FileMaker Knowldge Base
FileMaker Server 14.0.4a
Software Patch
• If you apply this software patch to your
FileMaker Server 14 installation, you will
enhance the security of your server. But
with this patch applied, if you enable the
Use SSL for database connections
setting in Admin Console, clients using
FileMaker Pro 12 or FileMaker Go 12 will
no longer be able to connect to solutions
hosted by your server.
- from FileMaker Knowldge Base
FileMaker 14.0.4
FileMaker 14.0.4
• FileMaker 14.0.4 includes changes to the
interaction between clients (FileMaker Pro
and FileMaker Go) and hosts (FileMaker
Server)
• the important security and product issue
fixes require updating both clients and
hosts to FileMaker 14.0.4 in order to fully
implement the fixes
- from FileMaker Knowldge Base
FileMaker, Inc. support policy
• Product updates are only offered for our
current products, and includes:
• Security updates
• Bug fixes
• Operating system compatibility updates
- from FileMaker Knowldge Base

Mais conteúdo relacionado

Destaque

Destaque (14)

Mac版FileMaker Serverで使えるコマンドライン活用レシピ
Mac版FileMaker Serverで使えるコマンドライン活用レシピMac版FileMaker Serverで使えるコマンドライン活用レシピ
Mac版FileMaker Serverで使えるコマンドライン活用レシピ
 
FileMaker Server Admin ConsoleとJavaの互換性まとめ(2014年版)
FileMaker Server Admin ConsoleとJavaの互換性まとめ(2014年版)FileMaker Server Admin ConsoleとJavaの互換性まとめ(2014年版)
FileMaker Server Admin ConsoleとJavaの互換性まとめ(2014年版)
 
FileMaker Pro 14.0.3とワイルドカードSSLサーバー証明書
FileMaker Pro 14.0.3とワイルドカードSSLサーバー証明書FileMaker Pro 14.0.3とワイルドカードSSLサーバー証明書
FileMaker Pro 14.0.3とワイルドカードSSLサーバー証明書
 
iPad & iPhoneからのリモートアクセスをより安全にするネットワーク構築術
iPad & iPhoneからのリモートアクセスをより安全にするネットワーク構築術iPad & iPhoneからのリモートアクセスをより安全にするネットワーク構築術
iPad & iPhoneからのリモートアクセスをより安全にするネットワーク構築術
 
Webアプリケーションフレームワークを利用した効率的なカスタムWeb開発
Webアプリケーションフレームワークを利用した効率的なカスタムWeb開発Webアプリケーションフレームワークを利用した効率的なカスタムWeb開発
Webアプリケーションフレームワークを利用した効率的なカスタムWeb開発
 
SSL暗号化通信を利用したネットワークセキュリティの向上
SSL暗号化通信を利用したネットワークセキュリティの向上SSL暗号化通信を利用したネットワークセキュリティの向上
SSL暗号化通信を利用したネットワークセキュリティの向上
 
PHP 5.4のビルトインウェブサーバー
PHP 5.4のビルトインウェブサーバーPHP 5.4のビルトインウェブサーバー
PHP 5.4のビルトインウェブサーバー
 
Mac OS X ServerのWebサービスとSSL暗号化通信
Mac OS X ServerのWebサービスとSSL暗号化通信Mac OS X ServerのWebサービスとSSL暗号化通信
Mac OS X ServerのWebサービスとSSL暗号化通信
 
SSL暗号化通信を利用したネットワークセキュリティの向上
SSL暗号化通信を利用したネットワークセキュリティの向上SSL暗号化通信を利用したネットワークセキュリティの向上
SSL暗号化通信を利用したネットワークセキュリティの向上
 
Exifの画像方向情報
Exifの画像方向情報Exifの画像方向情報
Exifの画像方向情報
 
INTER-MediatorによるWebアプリケーション開発入門
INTER-MediatorによるWebアプリケーション開発入門INTER-MediatorによるWebアプリケーション開発入門
INTER-MediatorによるWebアプリケーション開発入門
 
INTER-Mediator 5.0
INTER-Mediator 5.0INTER-Mediator 5.0
INTER-Mediator 5.0
 
INTER-MediatorによるWebアプリケーション開発入門(2014年版)
INTER-MediatorによるWebアプリケーション開発入門(2014年版)INTER-MediatorによるWebアプリケーション開発入門(2014年版)
INTER-MediatorによるWebアプリケーション開発入門(2014年版)
 
FMPress Publisher 3
FMPress Publisher 3FMPress Publisher 3
FMPress Publisher 3
 

Mais de Atsushi Matsuo

Mais de Atsushi Matsuo (20)

FMPress Formsの紹介とバージョン1.0.2の変更点
FMPress Formsの紹介とバージョン1.0.2の変更点FMPress Formsの紹介とバージョン1.0.2の変更点
FMPress Formsの紹介とバージョン1.0.2の変更点
 
Claris FileMaker Server for Linux 入門
Claris FileMaker Server for Linux 入門Claris FileMaker Server for Linux 入門
Claris FileMaker Server for Linux 入門
 
FMPress Formsの紹介
FMPress Formsの紹介FMPress Formsの紹介
FMPress Formsの紹介
 
fmcsadmin 1.3.0の新機能
fmcsadmin 1.3.0の新機能fmcsadmin 1.3.0の新機能
fmcsadmin 1.3.0の新機能
 
Integromatを使いノーコードでkintoneのレコードを作成
Integromatを使いノーコードでkintoneのレコードを作成Integromatを使いノーコードでkintoneのレコードを作成
Integromatを使いノーコードでkintoneのレコードを作成
 
INTER-Mediator 5.12とClaris FileMaker Server
INTER-Mediator 5.12とClaris FileMaker ServerINTER-Mediator 5.12とClaris FileMaker Server
INTER-Mediator 5.12とClaris FileMaker Server
 
オフライン環境でもkintoneのデータを活用する方法
オフライン環境でもkintoneのデータを活用する方法オフライン環境でもkintoneのデータを活用する方法
オフライン環境でもkintoneのデータを活用する方法
 
fmcsadmin 1.2.0の新機能
fmcsadmin 1.2.0の新機能fmcsadmin 1.2.0の新機能
fmcsadmin 1.2.0の新機能
 
Claris FileMaker Server 管理者が知っておきたい Infrastructure as Code
Claris FileMaker Server 管理者が知っておきたい Infrastructure as CodeClaris FileMaker Server 管理者が知っておきたい Infrastructure as Code
Claris FileMaker Server 管理者が知っておきたい Infrastructure as Code
 
Claris FileMaker Server 19.2で拡張されたFileMaker Admin API
Claris FileMaker Server 19.2で拡張されたFileMaker Admin APIClaris FileMaker Server 19.2で拡張されたFileMaker Admin API
Claris FileMaker Server 19.2で拡張されたFileMaker Admin API
 
FileMaker Server for LinuxでAD FSによる外部認証
FileMaker Server for LinuxでAD FSによる外部認証FileMaker Server for LinuxでAD FSによる外部認証
FileMaker Server for LinuxでAD FSによる外部認証
 
fmcsadmin 1.1.0
fmcsadmin 1.1.0fmcsadmin 1.1.0
fmcsadmin 1.1.0
 
Claris FileMaker Server 19の新機能と改善点
Claris FileMaker Server 19の新機能と改善点Claris FileMaker Server 19の新機能と改善点
Claris FileMaker Server 19の新機能と改善点
 
macOS版VirtualBoxにCentOS Linux 7をインストール
macOS版VirtualBoxにCentOS Linux 7をインストールmacOS版VirtualBoxにCentOS Linux 7をインストール
macOS版VirtualBoxにCentOS Linux 7をインストール
 
FileMaker Server 18とJava
FileMaker Server 18とJavaFileMaker Server 18とJava
FileMaker Server 18とJava
 
SSL暗号化通信を利用したネットワークセキュリティの向上(2020年版)
SSL暗号化通信を利用したネットワークセキュリティの向上(2020年版)SSL暗号化通信を利用したネットワークセキュリティの向上(2020年版)
SSL暗号化通信を利用したネットワークセキュリティの向上(2020年版)
 
Integromatを使いkintoneからSlackに通知を送る
Integromatを使いkintoneからSlackに通知を送るIntegromatを使いkintoneからSlackに通知を送る
Integromatを使いkintoneからSlackに通知を送る
 
fmcsadmin 1.0.0
fmcsadmin 1.0.0fmcsadmin 1.0.0
fmcsadmin 1.0.0
 
XMLPasteの紹介
XMLPasteの紹介XMLPasteの紹介
XMLPasteの紹介
 
FileMaker Admin API の使い方と活用方法
FileMaker Admin API の使い方と活用方法FileMaker Admin API の使い方と活用方法
FileMaker Admin API の使い方と活用方法
 

Último

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Último (20)

Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 

FileMaker Server 14.0.4 Security Updates

  • 1. FileMaker Server 14.0.4 Security Updates 2015/12/20 Lightning Talk in FM-Tokyo Atsushi Matsuo (Emic Corporation)
  • 3. FileMaker Server 14.0.4 • Includes security updates - from FileMaker Knowldge Base
  • 4. FileMaker Server 14.0.4 1. Addressed an issue related to the expiration of the default SSL certificate. - from FileMaker Knowldge Base
  • 5. FileMaker Server 14.0.4 2. Addressed an issue with the Technology Tests page link that tests Custom Web Publishing with PHP. - from FileMaker Knowldge Base
  • 6. FileMaker Server 14.0.4 • Fix XSS of the Technology Tests page that tests Custom Web Publishing with PHP • Affected: FileMaker Server 9, 10, 11, 12, 13, 14.0.1, 14.0.2, 14.0.3 (when enabling Custom Web Publishing with PHP) • Workaround: Remove "phptest.php" file - from results of my investigation
  • 7. FileMaker Server 14.0.4 3. For FileMaker WebDirect and Custom Web Publishing content to display in <iframe> tags of separate webpages, those webpages must also be hosted by the FileMaker Server web server.Webpages hosted by other web servers cannot use the <iframe> tag to embed FileMaker WebDirect and Custom Web Publishing content. - from FileMaker Knowldge Base
  • 8. FileMaker Server 14.0.4 • The web server of FileMaker Server 14.0.4 outputs "X-Frame-Options: SAMEORIGIN" HTTP header in order to prevente clickjacking - from results of my investigation
  • 10. FileMaker Server 14.0.4a Software Patch • This software provides security fixes for FileMaker Server 14.0.4 - from FileMaker Knowldge Base
  • 11. FileMaker Server 14.0.4a Software Patch 1. Updates the third-party component OpenSSL. - from FileMaker Knowldge Base
  • 12. FileMaker Server 14.0.4a Software Patch 2. Updates the third-party component Java to Java 8 Update 66, including a critical patch update. - from FileMaker Knowldge Base
  • 13. FileMaker Server 14.0.4a Software Patch 3. OS X El Capitan version 10.11:Addressed an issue where scripts using the Insert From URL script step returned an SSL certificate error. - from FileMaker Knowldge Base
  • 14. FileMaker Server 14.0.4a Software Patch • If you apply this software patch to your FileMaker Server 14 installation, you will enhance the security of your server. But with this patch applied, if you enable the Use SSL for database connections setting in Admin Console, clients using FileMaker Pro 12 or FileMaker Go 12 will no longer be able to connect to solutions hosted by your server. - from FileMaker Knowldge Base
  • 16. FileMaker 14.0.4 • FileMaker 14.0.4 includes changes to the interaction between clients (FileMaker Pro and FileMaker Go) and hosts (FileMaker Server) • the important security and product issue fixes require updating both clients and hosts to FileMaker 14.0.4 in order to fully implement the fixes - from FileMaker Knowldge Base
  • 17. FileMaker, Inc. support policy • Product updates are only offered for our current products, and includes: • Security updates • Bug fixes • Operating system compatibility updates - from FileMaker Knowldge Base