
Automated script suite to detect and remediate CVE-2025-46295 by replacing vulnerable Apache Commons JARs in FileMaker Server installations with dry-run, backup, and rollback support.
The FileMaker Apache Commons JAR Replacer is an automation solution that addresses CVE-2025-46295 by replacing vulnerable Apache Commons JAR files in FileMaker Server installations. Instead of upgrading the entire FileMaker Server, this solution follows the official Claris guidance to replace only the vulnerable commons-text and commons-lang3 JAR files with updated versions.
For most users, download the latest release instead of building from source:
Go to the Releases page
Download the appropriate file for your platform:
filemaker-jar-replacer-windows.zipfilemaker-jar-replacer-macos.tar.gzfilemaker-jar-replacer-ubuntu.tar.gzExtract and run - See the release notes for detailed extraction and usage instructions
The affected JAR files are installed only when the Web Publishing Engine is enabled for the first time.
This JAR replacer provides platform-specific scripts for:
replace-filemaker-jars-windows.ps1)replace-filemaker-jars-macos.sh)replace-filemaker-jars-ubuntu.sh)IMPORTANT: Before making any changes to your FileMaker Server, run the script with the --dry-run option to check if your server is vulnerable and see what changes would be made.
# Run PowerShell as Administrator
# Show help and available options
.\replace-filemaker-jars-windows.ps1 -Help
# Check if your server is vulnerable (RECOMMENDED FIRST STEP)
.\replace-filemaker-jars-windows.ps1 -DryRun
# Apply the security fix (only after reviewing dry-run results)
.\replace-filemaker-jars-windows.ps1
# Run with sudo privileges
# Show help and available options
sudo ./replace-filemaker-jars-macos.sh --help
# Check if your server is vulnerable (RECOMMENDED FIRST STEP)
sudo ./replace-filemaker-jars-macos.sh --dry-run
# Apply the security fix (only after reviewing dry-run results)
sudo ./replace-filemaker-jars-macos.sh
# Run with sudo privileges
# Show help and available options
sudo ./replace-filemaker-jars-ubuntu.sh --help
# Check if your server is vulnerable (RECOMMENDED FIRST STEP)
sudo ./replace-filemaker-jars-ubuntu.sh --dry-run
# Apply the security fix (only after reviewing dry-run results)
sudo ./replace-filemaker-jars-ubuntu.sh
The --dry-run option is the safest way to:
Always run with --dry-run first to understand what the script will do on your system.
filemaker-jar-replacer/
├── README.md # This file
├── replace-filemaker-jars-windows.ps1 # Windows PowerShell script
├── replace-filemaker-jars-macos.sh # macOS Bash script
├── replace-filemaker-jars-ubuntu.sh # Ubuntu Bash script
├── scripts/
│ ├── windows/
│ │ └── modules/ # PowerShell modules for JAR operations
│ ├── macos/
│ │ └── modules/ # Bash function modules for JAR operations
│ ├── ubuntu/
│ │ └── modules/ # Bash function modules for JAR operations
│ └── shared/ # Shared utilities and templates
├── config/
│ ├── logging-config.json # Logging configuration
│ └── jar-replacement-config.json # JAR replacement configuration
├── tests/ # Test suite (BATS and Pester)
├── logs/ # Log files (created during execution)
└── backups/ # JAR backup files (created during execution)
You can configure the updater using environment variables:
# FileMaker Server credentials
export FILEMAKER_USERNAME="admin"
export FILEMAKER_PASSWORD="your_secure_password"
# Custom paths (optional)
export FILEMAKER_INSTALL_PATH="/custom/path/to/filemaker"
export BACKUP_DIRECTORY="/custom/backup/path"
Create a .env file in the script directory:
# .env file (must have 600 permissions)
FILEMAKER_USERNAME=admin
FILEMAKER_PASSWORD=your_secure_password
BACKUP_DIRECTORY=/custom/backup/path
Important: Ensure .env file has restrictive permissions (600) for security.
If the automated script fails, follow these manual steps to replace the vulnerable JAR files:
# Using fmsadmin (recommended)
& "C:\Program Files\FileMaker\FileMaker Server\Database Server\fmsadmin.exe" stop wpe -u admin -p password