Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-46295-fix-fms — Automated script suite to detect and remediate CVE-2025-46295 by replacing vulnerable Apache Commons JARs in FileMaker Server installations with dry-run, backup, and rollback support. | Kitploit
Tools/GitHubGitHub/soliantconsulting/cve-2025-46295-fix-fms
Vulnerability ScannersVulnerability AnalysisScripting & AutomationConfiguration AuditingDevSecOpsSupply Chain Security
GitHubsoliantconsulting/cve-2025-46295-fix-fms

CVE-2025-46295-fix-fms

Automated script suite to detect and remediate CVE-2025-46295 by replacing vulnerable Apache Commons JARs in FileMaker Server installations with dry-run, backup, and rollback support.

View Repository
1129 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

FileMaker Apache Commons JAR Replacer

Overview

The FileMaker Apache Commons JAR Replacer is an automation solution that addresses CVE-2025-46295 by replacing vulnerable Apache Commons JAR files in FileMaker Server installations. Instead of upgrading the entire FileMaker Server, this solution follows the official Claris guidance to replace only the vulnerable commons-text and commons-lang3 JAR files with updated versions.

Quick Download

For most users, download the latest release instead of building from source:

Download Latest Release

  1. Go to the Releases page

  2. Download the appropriate file for your platform:

    • Windows: filemaker-jar-replacer-windows.zip
    • macOS: filemaker-jar-replacer-macos.tar.gz
    • Ubuntu/Linux: filemaker-jar-replacer-ubuntu.tar.gz
  3. Extract and run - See the release notes for detailed extraction and usage instructions

Why Use Releases?

  • ✅ Pre-tested - All releases are thoroughly tested across platforms
  • ✅ Ready to use - No compilation or setup required
  • ✅ Secure - Signed releases with checksums for verification
  • ✅ Complete - Includes all dependencies and documentation

Vulnerability Information

When is a server vulnerable?

The affected JAR files are installed only when the Web Publishing Engine is enabled for the first time.

CVE-2025-46295 Details

  • Severity: Critical
  • CVSS Score: 9.8 (Critical)
  • Affected Component: Apache Commons Text (versions prior to 1.10.0) and Apache Commons Lang (versions prior to 3.18.0)
  • Impact: Remote Code Execution
  • Affected FileMaker Versions: All versions with vulnerable JAR files
  • Solution: Replace vulnerable JAR files with updated versions (commons-text 1.11.0+, commons-lang3 3.18.0+)

Official Resources

  • Manual JAR Replacement Instructions (Without FileMaker Server Upgrade): https://support.claris.com/s/answerview?anum=000049055&language=en_US
  • CVE-2025-46295 Security Advisory (NIST): https://nvd.nist.gov/vuln/detail/CVE-2025-46295
  • Vulnerability Acknowledgment & Safe Version Confirmation: https://support.claris.com/s/answerview?anum=000049059&language=en_US

Supported Platforms

This JAR replacer provides platform-specific scripts for:

  • Windows: PowerShell script (replace-filemaker-jars-windows.ps1)
  • macOS: Bash script (replace-filemaker-jars-macos.sh)
  • Ubuntu: Bash script (replace-filemaker-jars-ubuntu.sh)

Quick Start

Prerequisites

Windows

  • Windows Server 2016+
  • PowerShell 5.1 or later
  • Administrator privileges
  • FileMaker Server installed

macOS

  • macOS 10.15 (Catalina) or later
  • Bash shell
  • sudo privileges
  • FileMaker Server installed

Ubuntu

  • Ubuntu 20.04 LTS or later
  • Bash shell
  • sudo privileges
  • FileMaker Server installed

Usage

IMPORTANT: Before making any changes to your FileMaker Server, run the script with the --dry-run option to check if your server is vulnerable and see what changes would be made.

Windows

# Run PowerShell as Administrator

# Show help and available options
.\replace-filemaker-jars-windows.ps1 -Help

# Check if your server is vulnerable (RECOMMENDED FIRST STEP)
.\replace-filemaker-jars-windows.ps1 -DryRun

# Apply the security fix (only after reviewing dry-run results)
.\replace-filemaker-jars-windows.ps1

macOS

# Run with sudo privileges

# Show help and available options
sudo ./replace-filemaker-jars-macos.sh --help

# Check if your server is vulnerable (RECOMMENDED FIRST STEP)
sudo ./replace-filemaker-jars-macos.sh --dry-run

# Apply the security fix (only after reviewing dry-run results)
sudo ./replace-filemaker-jars-macos.sh

Ubuntu

# Run with sudo privileges

# Show help and available options
sudo ./replace-filemaker-jars-ubuntu.sh --help

# Check if your server is vulnerable (RECOMMENDED FIRST STEP)
sudo ./replace-filemaker-jars-ubuntu.sh --dry-run

# Apply the security fix (only after reviewing dry-run results)
sudo ./replace-filemaker-jars-ubuntu.sh

Why Use Dry Run First?

The --dry-run option is the safest way to:

  • Check vulnerability status without making any changes
  • Identify which JAR files need to be replaced
  • Verify script compatibility with your FileMaker Server installation
  • Preview all actions that would be performed
  • Detect potential issues before making changes

Always run with --dry-run first to understand what the script will do on your system.

Features

Automated JAR Detection and Replacement

  • Automatically detects FileMaker Server installations and Web Publishing Engine directories
  • Identifies vulnerable commons-text and commons-lang3 JAR files
  • Downloads updated JAR files (commons-text 1.11.0+, commons-lang3 3.18.0+)
  • Performs atomic JAR file replacement with integrity verification

Comprehensive Backup and Recovery

  • Creates complete backup of existing JAR files before replacement
  • Automatic rollback on replacement failure
  • Backup integrity verification

Web Publishing Engine Management

  • Uses official fmsadmin command-line tool for service management
  • Secure credential handling for fmsadmin authentication
  • Automatic Web Publishing Engine restart after JAR replacement
  • Post-replacement functionality verification

Security-First Approach

  • Secure credential handling (never logged or displayed)
  • Supports environment variables and .env files
  • Validates file permissions for credential files

Detailed Logging

  • Comprehensive operation logging with timestamps
  • Platform-specific log locations
  • Error tracking and recovery guidance

User-Friendly Interface

  • Color-coded status indicators
  • Progress tracking for long operations
  • Clear error messages and recovery instructions

Directory Structure

filemaker-jar-replacer/
├── README.md                          # This file
├── replace-filemaker-jars-windows.ps1 # Windows PowerShell script
├── replace-filemaker-jars-macos.sh    # macOS Bash script
├── replace-filemaker-jars-ubuntu.sh   # Ubuntu Bash script
├── scripts/
│   ├── windows/
│   │   └── modules/                   # PowerShell modules for JAR operations
│   ├── macos/
│   │   └── modules/                   # Bash function modules for JAR operations
│   ├── ubuntu/
│   │   └── modules/                   # Bash function modules for JAR operations
│   └── shared/                        # Shared utilities and templates
├── config/
│   ├── logging-config.json           # Logging configuration
│   └── jar-replacement-config.json   # JAR replacement configuration
├── tests/                            # Test suite (BATS and Pester)
├── logs/                             # Log files (created during execution)
└── backups/                          # JAR backup files (created during execution)

Configuration

Environment Variables

You can configure the updater using environment variables:

# FileMaker Server credentials
export FILEMAKER_USERNAME="admin"
export FILEMAKER_PASSWORD="your_secure_password"

# Custom paths (optional)
export FILEMAKER_INSTALL_PATH="/custom/path/to/filemaker"
export BACKUP_DIRECTORY="/custom/backup/path"

.env File Support

Create a .env file in the script directory:

# .env file (must have 600 permissions)
FILEMAKER_USERNAME=admin
FILEMAKER_PASSWORD=your_secure_password
BACKUP_DIRECTORY=/custom/backup/path

Important: Ensure .env file has restrictive permissions (600) for security.

Manual JAR Replacement Process (Fallback)

If the automated script fails, follow these manual steps to replace the vulnerable JAR files:

1. Stop Web Publishing Engine

Windows

# Using fmsadmin (recommended)
& "C:\Program Files\FileMaker\FileMaker Server\Database Server\fmsadmin.exe" stop wpe -u admin -p password
Download Tool