← Vulnerability feed

Vulnerability record · CVE-2025-46294 · published 16 December 2025

CVE-2025-46294: Claris filemaker server information exposure vulnerability

Claris · Filemaker Server

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully addressed in FileMaker Server 22.0.4. The IIS Shortname Vulnerability exploits how Microsoft IIS handles legacy 8.3 short filenames, allowing attackers to infer the existence of files or directories by crafting requests with the tilde (~) character.

5.3 CVSS 3.1 Medium EPSS 0.23% · top 87.1% CWE-200 · Information exposure
5.3CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully addressed in FileMaker Server 22.0.4. The IIS Shortname Vulnerability exploits how Microsoft IIS handles legacy 8.3 short filenames, allowing attackers to infer the existence of files or directories by crafting requests with the tilde (~) character.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-46294 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-46295Claris filemaker server code injection vulnerabilityApache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the t…EPSS 1.0%7.5CVE-2024-27790Claris filemaker server improper access control vulnerabilityClaris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. Thi…EPSS 0.46%6.1CVE-2025-46320Claris filemaker server cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This…EPSS 0.22%6.1CVE-2024-27794Claris filemaker server cross-site scripting vulnerabilityClaris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled paramete…EPSS 0.31%5.5CVE-2021-44147Claris filemaker pro xml external entity (xxe) vulnerabilityAn XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files …EPSS 1.2%5.4CVE-2025-46296Claris filemaker server improper authorization vulnerabilityAn authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative …EPSS 0.17%4.9CVE-2026-43752Claris filemaker server unrestricted file upload vulnerabilityAn authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Sour…EPSS 0.49%4.9CVE-2023-42955Claris filemaker server insufficiently protected credentials vulnerabilityClaris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admi…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2025-46294), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.